CVE Tools

Fedora

6,154 CVEs tracked. 89 of them are in CISA KEV.

This hub aggregates every CVE we track for Fedora, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Fedora CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Fedora CVEs per month
MonthCVEs
2024-1021
2024-1157
2024-1211
2025-0116
2025-021
2025-0311
2025-0415
2025-057
2025-0620
2025-0711
2025-088
2025-096
2025-101
2025-1118
2025-1222
2026-0110
2026-029
2026-0318
2026-042
2026-051
2026-062
2026-070
2026-080
2026-092

Severity

How the 6,154 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical5178%
  • High2,69244%
  • Medium2,67844%
  • Low2674%

Latest CVEs

The 15 most recently published vulnerabilities affecting Fedora.

  1. CVE-2026-19816PackageKit: dnf5 backend ignores SIMULATE on RepoRemove7.1
  2. CVE-2026-19624NetworkManager-l2tp: local privilege escalation via ipsec.conf injection7.8
  3. CVE-2026-54231Abrt: unsanitized systemd journal content written to dump directory files enables content injection5.5
  4. CVE-2026-54230Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites7.0
  5. CVE-2026-43284xfrm: esp: avoid in-place decrypt on shared skb frags8.8
  6. CVE-2026-35094Libinput: libinput: information disclosure via dangling pointer in lua plugin handling3.3
  7. CVE-2026-35093Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins8.8
  8. CVE-2026-25645Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function4.4
  9. CVE-2026-2369Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources6.5
  10. CVE-2026-3941Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity:...4.3
  11. CVE-2026-3942Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)4.3
  12. CVE-2026-3939Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file. (Chromium security severity: Low)5.3
  13. CVE-2026-3940Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity:...5.3
  14. CVE-2026-3938Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML ...4.3
  15. CVE-2026-3937Incorrect security UI in Downloads in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store