Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Centos

First CVE: Dec 18, 2007Active for: 19 yearsTotal CVEs: 8

CentOS maintains a narrowly scoped product line centered on its community-driven Linux distribution and its rolling-release Stream variant, which serve as widely deployed foundational platforms for enterprise and infrastructure workloads. Vulnerabilities affecting CentOS carry an elevated tendency toward confirmed in-the-wild exploitation and public exploit availability, reflecting the distribution's role in high-value server environments and the broad downstream impact of kernel and system library flaws; the recurring weakness classes, including information disclosure, improper locking, SQL injection, and privilege-management issues, are typical of systemic software where flaws in core components propagate across dependent applications. Defenders should prioritize patching cycles for this vendor given the exploitation profile and treat CentOS systems, especially internet-facing or privileged instances, as high-value remediation targets; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
12.5%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Centos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2007
18 years ago
Most Recent CVE
Aug 10, 2022
1,443 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-1000253HIGH
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This ker
Oct 5, 20177.876YESYES
CVE-2019-19906HIGH
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ult
Dec 19, 20197.529NONO
CVE-2020-5291HIGH
Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the
Mar 31, 20207.825NONO
CVE-2022-24121HIGH
SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter.
Feb 3, 20227.524NONO
CVE-2021-20315MEDIUM
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enab
Feb 18, 20226.122NONO
CVE-2022-23238MEDIUM
Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerab
Aug 10, 20226.521NONO
CVE-2011-4144MEDIUM
Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local users to obtain "highest super user priv
Feb 2, 20126.820NONO
CVE-2007-6283MEDIUM
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as
Dec 18, 20074.916NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
50%
50%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (25.0%)
Network3 (37.5%)
Unknown2 (25.0%)
Physical1 (12.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High0 (0.0%)
Unknown2 (25.0%)
User Interaction
None6 (75.0%)
Unknown2 (25.0%)
Required0 (0.0%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None4 (50.0%)
Unknown2 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
1 CVE
12.5% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Centos.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Centos — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Centos's Products

View all 4 CNAs →

Top CWEs