Fedora-project
1,989 CVEs tracked since 2008. Since Aug 2020, 29 of them reached CISA KEV.
Fedora-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-08 | 16 | 1 |
| 2020-09 | 44 | 0 |
| 2020-10 | 26 | 0 |
| 2020-11 | 41 | 2 |
| 2020-12 | 27 | 1 |
| 2021-01 | 13 | 1 |
| 2021-02 | 33 | 1 |
| 2021-03 | null or fewer | |
| 2021-04 | 30 | 3 |
| 2021-05 | 18 | 0 |
| 2021-06 | 22 | 1 |
| 2021-07 | 27 | 1 |
| 2021-08 | 27 | 2 |
| 2021-09 | 29 | 3 |
| 2021-10 | 39 | 4 |
| 2021-11 | 19 | 1 |
| 2021-12 | 19 | 0 |
| 2022-01 | 22 | 2 |
| 2022-02 | 39 | 0 |
| 2022-03 | 25 | 0 |
| 2022-04 | 21 | 0 |
| 2022-05 | 31 | 0 |
| 2022-06 | 40 | 0 |
| 2022-07 | 23 | 0 |
| 2022-08 | 15 | 0 |
| 2022-09 | 23 | 0 |
| 2022-10 | 21 | 0 |
| 2022-11 | 34 | 0 |
| 2022-12 | 4 | 0 |
| 2023-01 | 4 | 0 |
| 2023-02 | 21 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 19 | 0 |
| 2023-05 | 24 | 0 |
| 2023-06 | 19 | 0 |
| 2023-07 | 38 | 0 |
| 2023-08 | 45 | 0 |
| 2023-09 | 26 | 1 |
| 2023-10 | 21 | 2 |
| 2023-11 | 9 | 1 |
| 2023-12 | 22 | 1 |
| 2024-01 | 37 | 1 |
| 2024-02 | 34 | 0 |
| 2024-03 | 35 | 0 |
| 2024-04 | 62 | 0 |
| 2024-05 | 64 | 0 |
| 2024-06 | 28 | 0 |
| 2024-07 | 6 | 0 |
| 2024-08 | 4 | 0 |
| 2024-09 | 12 | 0 |
| 2024-10 | 22 | 0 |
| 2024-11 | 50 | 0 |
| 2024-12 | 11 | 0 |
| 2025-01 | 16 | 0 |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | 14 | 0 |
| 2025-05 | 6 | 0 |
| 2025-06 | 21 | 0 |
| 2025-07 | 11 | 0 |
| 2025-08 | 7 | 0 |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | 18 | 0 |
| 2025-12 | 17 | 0 |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | null or fewer | |
| 2026-05 | null or fewer | |
| 2026-06 | 14 | 0 |
Products
The products that kept showing up in Fedora-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Fedora-project.
- CVE-2026-77118Out-of-bounds write in GraphicsMagick PCD decoder—
- CVE-2026-11236Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v...8.3
- CVE-2026-11237Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted H...8.3
- CVE-2026-11235Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox ...8.8
- CVE-2026-11233Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted...4.7
- CVE-2026-11232Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)5.4
- CVE-2026-11231Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)8.1
- CVE-2026-11230Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)8.8
- CVE-2026-11229Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security sev...6.1
- CVE-2026-11228Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a craf...4.3
- CVE-2026-11227Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)6.5
- CVE-2026-11224Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)8.1
- CVE-2026-11223Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a c...6.5
- CVE-2026-11225Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)6.5
- CVE-2026-11222Incorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)6.5
The record
- Peak rank
- #13 in Dec 2019
- Busiest month shown
- May 2024, 64 CVEs
- Months with a KEV entry
- 18 since Aug 2020
- Monthly snapshots
- 103 since 2008