Fedoraproject
4,697 CVEs tracked since 2005. Since Sep 2018, 77 of them reached CISA KEV.
Fedoraproject CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2018-09 | 7 | 0 |
| 2018-10 | 8 | 0 |
| 2018-11 | null or fewer | |
| 2018-12 | 29 | 0 |
| 2019-01 | null or fewer | |
| 2019-02 | 59 | 0 |
| 2019-03 | null or fewer | |
| 2019-04 | null or fewer | |
| 2019-05 | 26 | 0 |
| 2019-06 | null or fewer | |
| 2019-07 | 60 | 1 |
| 2019-08 | 40 | 0 |
| 2019-09 | 45 | 1 |
| 2019-10 | 67 | 1 |
| 2019-11 | 109 | 0 |
| 2019-12 | 111 | 1 |
| 2020-01 | 45 | 1 |
| 2020-02 | 72 | 2 |
| 2020-03 | 46 | 0 |
| 2020-04 | null or fewer | |
| 2020-05 | null or fewer | |
| 2020-06 | 82 | 1 |
| 2020-07 | null or fewer | |
| 2020-08 | 42 | 1 |
| 2020-09 | 95 | 0 |
| 2020-10 | 55 | 0 |
| 2020-11 | 82 | 5 |
| 2020-12 | 58 | 1 |
| 2021-01 | 72 | 2 |
| 2021-02 | 82 | 1 |
| 2021-03 | null or fewer | |
| 2021-04 | 124 | 7 |
| 2021-05 | 92 | 0 |
| 2021-06 | 109 | 2 |
| 2021-07 | 63 | 1 |
| 2021-08 | 123 | 3 |
| 2021-09 | 59 | 1 |
| 2021-10 | 100 | 8 |
| 2021-11 | 79 | 3 |
| 2021-12 | 90 | 2 |
| 2022-01 | 77 | 1 |
| 2022-02 | 133 | 0 |
| 2022-03 | 111 | 2 |
| 2022-04 | 58 | 0 |
| 2022-05 | 71 | 0 |
| 2022-06 | 52 | 0 |
| 2022-07 | 91 | 1 |
| 2022-08 | 113 | 1 |
| 2022-09 | 98 | 3 |
| 2022-10 | 54 | 0 |
| 2022-11 | 69 | 0 |
| 2022-12 | 20 | 0 |
| 2023-01 | 19 | 0 |
| 2023-02 | 13 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 54 | 2 |
| 2023-05 | 45 | 0 |
| 2023-06 | 33 | 2 |
| 2023-07 | 48 | 0 |
| 2023-08 | 82 | 1 |
| 2023-09 | 68 | 4 |
| 2023-10 | 57 | 3 |
| 2023-11 | 62 | 3 |
| 2023-12 | 27 | 2 |
| 2024-01 | 56 | 2 |
| 2024-02 | 69 | 0 |
| 2024-03 | 41 | 0 |
| 2024-04 | 77 | 0 |
| 2024-05 | 86 | 4 |
| 2024-06 | 30 | 1 |
Products
The products that kept showing up in Fedoraproject's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Fedoraproject.
- CVE-2026-68743Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v15.5
- CVE-2026-68744Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply3.3
- CVE-2026-68742Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr5.5
- CVE-2026-12610Sssd: use-after-free crash in sssd' 'sssd_pam' process6.4
- CVE-2026-54231Abrt: unsanitized systemd journal content written to dump directory files enables content injection5.5
- CVE-2026-54230Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites7.0
- CVE-2026-6245Sssd: out-of-bounds read in the sssd5.5
- CVE-2026-35094Libinput: libinput: information disclosure via dangling pointer in lua plugin handling3.3
- CVE-2026-35093Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins8.8
- CVE-2023-4134Kernel: cyttsp4_core: use-after-free in cyttsp4_watchdog_work()5.5
- CVE-2024-3056Podman: kernel: containers in shared ipc namespace are vulnerable to denial of service attack7.7
- CVE-2024-6293Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2024-6291Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2024-6290Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
- CVE-2024-6292Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
The record
- Peak rank
- #3 in Feb 2022
- Busiest month shown
- Feb 2022, 133 CVEs
- Months with a KEV entry
- 35 since Sep 2018
- Monthly snapshots
- 178 since 2005