CVE Tools

Fedora-project

1,989 CVEs tracked since 2008. Since Aug 2020, 29 of them reached CISA KEV.

Fedora-project CVEs per month

Aug 2020 to Jun 2026. Point at a month, or focus the strip and use the arrow keys.
Fedora-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-08161
2020-09440
2020-10260
2020-11412
2020-12271
2021-01131
2021-02331
2021-03null or fewer
2021-04303
2021-05180
2021-06221
2021-07271
2021-08272
2021-09293
2021-10394
2021-11191
2021-12190
2022-01222
2022-02390
2022-03250
2022-04210
2022-05310
2022-06400
2022-07230
2022-08150
2022-09230
2022-10210
2022-11340
2022-1240
2023-0140
2023-02210
2023-03null or fewer
2023-04190
2023-05240
2023-06190
2023-07380
2023-08450
2023-09261
2023-10212
2023-1191
2023-12221
2024-01371
2024-02340
2024-03350
2024-04620
2024-05640
2024-06280
2024-0760
2024-0840
2024-09120
2024-10220
2024-11500
2024-12110
2025-01160
2025-02null or fewer
2025-03null or fewer
2025-04140
2025-0560
2025-06210
2025-07110
2025-0870
2025-09null or fewer
2025-10null or fewer
2025-11180
2025-12170
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06140

Products

The products that kept showing up in Fedora-project's monthly top three, with their CVEs summed over those months.

  1. Fedora1,43659 months
  2. Fedora Epel7611 months
  3. 389 Directory Server119 months
  4. Nbdkit Plugin Framework21 month
  5. Coreos11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Fedora-project.

  1. CVE-2026-77118Out-of-bounds write in GraphicsMagick PCD decoder—
  2. CVE-2026-11236Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v...8.3
  3. CVE-2026-11237Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted H...8.3
  4. CVE-2026-11235Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox ...8.8
  5. CVE-2026-11233Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted...4.7
  6. CVE-2026-11232Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)5.4
  7. CVE-2026-11231Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)8.1
  8. CVE-2026-11230Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)8.8
  9. CVE-2026-11229Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security sev...6.1
  10. CVE-2026-11228Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a craf...4.3
  11. CVE-2026-11227Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)6.5
  12. CVE-2026-11224Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)8.1
  13. CVE-2026-11223Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a c...6.5
  14. CVE-2026-11225Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)6.5
  15. CVE-2026-11222Incorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)6.5

The record

Peak rank
#13 in Dec 2019
Busiest month shown
May 2024, 64 CVEs
Months with a KEV entry
18 since Aug 2020
Monthly snapshots
103 since 2008
Fedora-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store