Debian Linux
Vendor:
First CVE: Dec 19, 1994 · Active for 31 years
10,068
Total CVEs
More Total CVEs than 100% of tracked products
314.6
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
1.2%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Debian Linux over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 1994
31 years ago
Most Recent CVE
Jul 3, 2026
21 days ago
CVE Severity & Scoring
Debian Linux10,068 CVEs
43%
43%
10%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3,096 (30.8%)
Network5,621 (55.8%)
Unknown1,201 (11.9%)
Physical63 (0.6%)
Adjacent Network87 (0.9%)
Attack Complexity
Low7,904 (78.5%)
High963 (9.6%)
Unknown1,201 (11.9%)
User Interaction
None5,785 (57.5%)
Unknown1,201 (11.9%)
Required3,082 (30.6%)
Privileges Required
Low2,608 (25.9%)
High257 (2.6%)
None6,002 (59.6%)
Unknown1,201 (11.9%)
Top CVEs
Signals from CVEs in this product scope (10068 CVEs).
10,068 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31431HIGH In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the c | Apr 22, 2026 | 7.8 | 99 | YES | YES |
CVE-2026-24061CRITICAL telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. | Jan 21, 2026 | 9.8 | 99 | YES | YES |
CVE-2025-49113HIGH Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions | Jun 2, 2025 | 8.8 | 99 | YES | YES |
CVE-2025-24813CRITICAL Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau | Mar 10, 2025 | 9.8 | 99 | YES | YES |
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2021-3156HIGH Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg | Jan 26, 2021 | 7.8 | 99 | YES | YES |
CVE-2020-1472CRITICAL An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc | Aug 17, 2020 | 10.0 | 99 | YES | YES |
CVE-2020-1938CRITICAL When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e | Feb 24, 2020 | 9.8 | 99 | YES | YES |
CVE-2020-7247CRITICAL smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP sessio | Jan 29, 2020 | 9.8 | 99 | YES | YES |
CVE-2019-5418HIGH There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrar | Mar 27, 2019 | 7.5 | 99 | YES | YES |
Exploit Exposure
Signals from CVEs in this product scope (10068 CVEs).
CISA KEV
122 CVEs
1.2% of CVEs· 96th percentile
Metasploit
127 CVEs
1.3% of CVEs· 96th percentile
Nuclei
80 CVEs
0.8% of CVEs· 96th percentile
ExploitDB
353 CVEs
3.5% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (10068 CVEs).
Media Mentions
Signals from CVEs in this product scope (10068 CVEs).
Top CNAs Publishing CVEs For Debian Linux
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.2 | 1 | 7.8 | 1.3% | 0 | 0 |
| 9.0 | 3,994 | 7.2 | 6.8% | 39 | 176 |
| 8.0 | 3,475 | 7.1 | 6.1% | 21 | 174 |
| 7.1 | 14 | 7.4 | 44.4% | 0 | 8 |
| 7.0 | 1,250 | 6.7 | 7.9% | 14 | 78 |
| 6.2 | 1 | 7.5 | 2.2% | 0 | 0 |
| 6.0 | 254 | 6.5 | 10.1% | 4 | 26 |
| 5.0 | 183 | 6.0 | 10.2% | 3 | 33 |
| 4.0 | 178 | 6.8 | 7.6% | 1 | 25 |
| 3.1 | 109 | 5.3 | 4.2% | 0 | 15 |
| 3.0.23 | 1 | 7.2 | 0.9% | 0 | 1 |
| 3.0.18 | 1 | 7.2 | 0.9% | 0 | 1 |
| 3.0 | 97 | 6.5 | 4.4% | 0 | 12 |
| 2.3 | 10 | 7.0 | 10.0% | 0 | 4 |
| 2.2 | 58 | 5.6 | 4.7% | 0 | 19 |
| 2.1 | 26 | 6.4 | 2.9% | 0 | 10 |
| 2.0.5 | 1 | 7.2 | 0.8% | 0 | 1 |
| 2.0.34 | 2 | 5.0 | 1.8% | 0 | 0 |
| 2.0 | 16 | 7.3 | 3.8% | 0 | 8 |
| 1.3.1 | 5 | 6.7 | 0.6% | 0 | 1 |