Debian Linux

Vendor:

First CVE: Dec 19, 1994 · Active for 31 years

10,068
Total CVEs
More Total CVEs than 100% of tracked products
314.6
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
1.2%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Debian Linux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 1994
31 years ago
Most Recent CVE
Jul 3, 2026
21 days ago

CVE Severity & Scoring

Debian Linux10,068 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local3,096 (30.8%)
Network5,621 (55.8%)
Unknown1,201 (11.9%)
Physical63 (0.6%)
Adjacent Network87 (0.9%)
Attack Complexity
Low7,904 (78.5%)
High963 (9.6%)
Unknown1,201 (11.9%)
User Interaction
None5,785 (57.5%)
Unknown1,201 (11.9%)
Required3,082 (30.6%)
Privileges Required
Low2,608 (25.9%)
High257 (2.6%)
None6,002 (59.6%)
Unknown1,201 (11.9%)

Top CVEs

Signals from CVEs in this product scope (10068 CVEs).

10,068 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c
Apr 22, 20267.899YESYES
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Jan 21, 20269.899YESYES
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions
Jun 2, 20258.899YESYES
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau
Mar 10, 20259.899YESYES
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc
Aug 17, 202010.099YESYES
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP sessio
Jan 29, 20209.899YESYES
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrar
Mar 27, 20197.599YESYES

Exploit Exposure

Signals from CVEs in this product scope (10068 CVEs).

CISA KEV
122 CVEs
1.2% of CVEs· 96th percentile
Metasploit
127 CVEs
1.3% of CVEs· 96th percentile
Nuclei
80 CVEs
0.8% of CVEs· 96th percentile
ExploitDB
353 CVEs
3.5% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (10068 CVEs).

Media Mentions

Signals from CVEs in this product scope (10068 CVEs).

Top CNAs Publishing CVEs For Debian Linux

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.217.81.3%00
9.03,9947.26.8%39176
8.03,4757.16.1%21174
7.1147.444.4%08
7.01,2506.77.9%1478
6.217.52.2%00
6.02546.510.1%426
5.01836.010.2%333
4.01786.87.6%125
3.11095.34.2%015
3.0.2317.20.9%01
3.0.1817.20.9%01
3.0976.54.4%012
2.3107.010.0%04
2.2585.64.7%019
2.1266.42.9%010
2.0.517.20.8%01
2.0.3425.01.8%00
2.0167.33.8%08
1.3.156.70.6%01