Debian
20,497 CVEs tracked. 170 of them are in CISA KEV.
This hub aggregates every CVE we track for Debian, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Debian CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 364 |
| 2024-11 | 217 |
| 2024-12 | 271 |
| 2025-01 | 192 |
| 2025-02 | 349 |
| 2025-03 | 151 |
| 2025-04 | 151 |
| 2025-05 | 311 |
| 2025-06 | 220 |
| 2025-07 | 272 |
| 2025-08 | 134 |
| 2025-09 | 475 |
| 2025-10 | 331 |
| 2025-11 | 99 |
| 2025-12 | 271 |
| 2026-01 | 102 |
| 2026-02 | 49 |
| 2026-03 | 132 |
| 2026-04 | 84 |
| 2026-05 | 105 |
| 2026-06 | 30 |
| 2026-07 | 2 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 20,497 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1,885
- High8,746
- Medium9,111
- Low755
Latest CVEs
The 15 most recently published vulnerabilities affecting Debian.
- CVE-2026-12996A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TL...8.1
- CVE-2026-14355ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD5.6
- CVE-2026-56968GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.3.7
- CVE-2026-46331net/sched: fix pedit partial COW leading to page cache corruption7.8
- CVE-2026-46520ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions7.5
- CVE-2026-45664ImageMagick: Policy Bypass in MNG coder could5.3
- CVE-2026-49975Apache HTTP Server: mod_http2 denial of service7.5
- CVE-2026-3238Samba: denial of service against ad dc wins server7.5
- CVE-2026-11236Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v...8.3
- CVE-2026-11237Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted H...8.3
- CVE-2026-11235Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox ...8.8
- CVE-2026-11233Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted...4.7
- CVE-2026-11232Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)5.4
- CVE-2026-11231Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)8.1
- CVE-2026-11230Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)8.8
Product grouping is registry-driven, with AI assist and human review. How it works