CVE Tools

Fedoraproject

4,697 CVEs tracked since 2005. Since Sep 2018, 77 of them reached CISA KEV.

Fedoraproject CVEs per month

Sep 2018 to Jun 2024. Point at a month, or focus the strip and use the arrow keys.
Fedoraproject CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0970
2018-1080
2018-11null or fewer
2018-12290
2019-01null or fewer
2019-02590
2019-03null or fewer
2019-04null or fewer
2019-05260
2019-06null or fewer
2019-07601
2019-08400
2019-09451
2019-10671
2019-111090
2019-121111
2020-01451
2020-02722
2020-03460
2020-04null or fewer
2020-05null or fewer
2020-06821
2020-07null or fewer
2020-08421
2020-09950
2020-10550
2020-11825
2020-12581
2021-01722
2021-02821
2021-03null or fewer
2021-041247
2021-05920
2021-061092
2021-07631
2021-081233
2021-09591
2021-101008
2021-11793
2021-12902
2022-01771
2022-021330
2022-031112
2022-04580
2022-05710
2022-06520
2022-07911
2022-081131
2022-09983
2022-10540
2022-11690
2022-12200
2023-01190
2023-02130
2023-03null or fewer
2023-04542
2023-05450
2023-06332
2023-07480
2023-08821
2023-09684
2023-10573
2023-11623
2023-12272
2024-01562
2024-02690
2024-03410
2024-04770
2024-05864
2024-06301

Products

The products that kept showing up in Fedoraproject's monthly top three, with their CVEs summed over those months.

  1. Fedora3,93160 months
  2. Extra Packages For Enterprise Linux7428 months
  3. 389 Directory Server74 months
  4. Sssd55 months
  5. Fedora Linux Kernel11 month
  6. Sectool11 month
  7. Selinux-policy11 month
  8. Supybot-fedora11 month
  9. Unbound11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Fedoraproject.

  1. CVE-2026-68743Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v15.5
  2. CVE-2026-68744Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply3.3
  3. CVE-2026-68742Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr5.5
  4. CVE-2026-12610Sssd: use-after-free crash in sssd' 'sssd_pam' process6.4
  5. CVE-2026-54231Abrt: unsanitized systemd journal content written to dump directory files enables content injection5.5
  6. CVE-2026-54230Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites7.0
  7. CVE-2026-6245Sssd: out-of-bounds read in the sssd5.5
  8. CVE-2026-35094Libinput: libinput: information disclosure via dangling pointer in lua plugin handling3.3
  9. CVE-2026-35093Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins8.8
  10. CVE-2023-4134Kernel: cyttsp4_core: use-after-free in cyttsp4_watchdog_work()5.5
  11. CVE-2024-3056Podman: kernel: containers in shared ipc namespace are vulnerable to denial of service attack7.7
  12. CVE-2024-6293Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
  13. CVE-2024-6291Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
  14. CVE-2024-6290Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8
  15. CVE-2024-6292Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)8.8

The record

Peak rank
#3 in Feb 2022
Busiest month shown
Feb 2022, 133 CVEs
Months with a KEV entry
35 since Sep 2018
Monthly snapshots
178 since 2005
Fedoraproject's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store