CentOS maintains a narrowly scoped product line centered on its community-driven Linux distribution and its rolling-release Stream variant, which serve as widely deployed foundational platforms for enterprise and infrastructure workloads. Vulnerabilities affecting CentOS carry an elevated tendency toward confirmed in-the-wild exploitation and public exploit availability, reflecting the distribution's role in high-value server environments and the broad downstream impact of kernel and system library flaws; the recurring weakness classes, including information disclosure, improper locking, SQL injection, and privilege-management issues, are typical of systemic software where flaws in core components propagate across dependent applications. Defenders should prioritize patching cycles for this vendor given the exploitation profile and treat CentOS systems, especially internet-facing or privileged instances, as high-value remediation targets; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Centos over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000253HIGH Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This ker | Oct 5, 2017 | 7.8 | 76 | YES | YES |
CVE-2019-19906HIGH cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ult | Dec 19, 2019 | 7.5 | 29 | NO | NO |
CVE-2020-5291HIGH Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the | Mar 31, 2020 | 7.8 | 25 | NO | NO |
CVE-2022-24121HIGH SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter. | Feb 3, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-20315MEDIUM A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enab | Feb 18, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-23238MEDIUM Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerab | Aug 10, 2022 | 6.5 | 21 | NO | NO |
CVE-2011-4144MEDIUM Unspecified vulnerability in EMC Documentum Content Server 6.0, 6.5 before SP2 P02, 6.5 SP3 before SP3 P02, and 6.6 before P02 allows local users to obtain "highest super user priv | Feb 2, 2012 | 6.8 | 20 | NO | NO |
CVE-2007-6283MEDIUM Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as | Dec 18, 2007 | 4.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Centos.
Media articles that mention a CVE ID that affects a product developed by Centos — matched by CVE ID, not by vendor name.