Debian
8,689 CVEs tracked since 1999. Since Sep 2020, 71 of them reached CISA KEV.
Debian CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-09 | 104 | 0 |
| 2020-10 | 65 | 0 |
| 2020-11 | 95 | 4 |
| 2020-12 | 96 | 1 |
| 2021-01 | 82 | 2 |
| 2021-02 | 62 | 2 |
| 2021-03 | null or fewer | |
| 2021-04 | 116 | 3 |
| 2021-05 | 100 | 0 |
| 2021-06 | 71 | 0 |
| 2021-07 | 47 | 0 |
| 2021-08 | 122 | 3 |
| 2021-09 | 89 | 1 |
| 2021-10 | 75 | 3 |
| 2021-11 | 88 | 3 |
| 2021-12 | 108 | 3 |
| 2022-01 | 111 | 2 |
| 2022-02 | 95 | 2 |
| 2022-03 | 99 | 1 |
| 2022-04 | 108 | 0 |
| 2022-05 | 73 | 1 |
| 2022-06 | 45 | 0 |
| 2022-07 | 68 | 0 |
| 2022-08 | 69 | 1 |
| 2022-09 | 80 | 0 |
| 2022-10 | 66 | 0 |
| 2022-11 | 65 | 0 |
| 2022-12 | 78 | 0 |
| 2023-01 | 23 | 1 |
| 2023-02 | 14 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 48 | 2 |
| 2023-05 | 48 | 0 |
| 2023-06 | 34 | 2 |
| 2023-07 | 37 | 0 |
| 2023-08 | 98 | 0 |
| 2023-09 | 54 | 5 |
| 2023-10 | 48 | 4 |
| 2023-11 | 36 | 3 |
| 2023-12 | 39 | 2 |
| 2024-01 | 22 | 1 |
| 2024-02 | 33 | 0 |
| 2024-03 | 47 | 0 |
| 2024-04 | 124 | 0 |
| 2024-05 | 189 | 0 |
| 2024-06 | 13 | 2 |
| 2024-07 | 5 | 0 |
| 2024-08 | null or fewer | |
| 2024-09 | 12 | 0 |
| 2024-10 | 16 | 1 |
| 2024-11 | 14 | 3 |
| 2024-12 | 8 | 3 |
| 2025-01 | 10 | 0 |
| 2025-02 | 10 | 0 |
| 2025-03 | 10 | 3 |
| 2025-04 | 14 | 1 |
| 2025-05 | 145 | 0 |
| 2025-06 | 55 | 2 |
| 2025-07 | 201 | 3 |
| 2025-08 | 77 | 0 |
| 2025-09 | 139 | 1 |
| 2025-10 | 14 | 0 |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | 7 | 0 |
Products
The products that kept showing up in Debian's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Debian.
- CVE-2026-89169live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.—
- CVE-2026-77118Out-of-bounds write in GraphicsMagick PCD decoder—
- CVE-2026-12996A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TL...8.1
- CVE-2026-14355ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD5.6
- CVE-2026-56968GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.3.7
- CVE-2026-11853Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest files that name the file...6.5
- CVE-2026-11852Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create and delete relati...6.5
- CVE-2026-49975Apache HTTP Server: mod_http2 denial of service7.5
- CVE-2026-9256NGINX ngx_http_rewrite_module vulnerability8.1
- CVE-2026-46333ptrace: slightly saner 'get_dumpable()' logic7.1
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place7.8
- CVE-2026-41082In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.7.3
- CVE-2026-34757LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure5.1
- CVE-2026-4775Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing7.8
- CVE-2026-1940Gstreamer: incomplete fix of cve-2026-19405.1
The record
- Peak rank
- #1 in Sep 2018
- Busiest month shown
- Jul 2025, 201 CVEs
- Months with a KEV entry
- 32 since Sep 2020
- Monthly snapshots
- 263 since 1999