Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fedora Project

First CVE: Oct 25, 2005Active for: 21 yearsTotal CVEs: 5,472

Fedora Project's minimal disclosure footprint centers on its community Linux distribution and development releases, which are inherently subject to upstream component vulnerabilities that Fedora itself does not originate. The durable signal is anchored in input-validation issues within bundled packages rather than Fedora-specific flaws, reflecting the distribution's role as an integration point for broader open-source software; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5,472
Total CVEs
More Total CVEs than 56% of tracked vendors
10.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
1.6%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fedora Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2005
20 years ago
Most Recent CVE
Jun 30, 2026
24 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (5472 CVEs).

5,472 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-4577CRITICAL
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows m
Jun 9, 20249.899YESYES
CVE-2021-44228CRITICAL
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
CVE-2021-42013CRITICAL
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori
Oct 7, 20219.899YESYES
CVE-2021-41773CRITICAL
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con
Oct 5, 20219.899YESYES
CVE-2021-3156HIGH
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
CVE-2020-1472CRITICAL
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc
Aug 17, 202010.099YESYES
CVE-2020-1938CRITICAL
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
CVE-2020-7247CRITICAL
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP sessio
Jan 29, 20209.899YESYES
CVE-2019-5418HIGH
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrar
Mar 27, 20197.599YESYES
CVE-2014-0160HIGH
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform
Apr 7, 20147.599YESYES
View all 5,472 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5,472 CVEs
43%
44%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1,359 (24.8%)
Network3,622 (66.2%)
Unknown425 (7.8%)
Physical30 (0.5%)
Adjacent Network36 (0.7%)
Attack Complexity
Low4,543 (83.0%)
High504 (9.2%)
Unknown425 (7.8%)
User Interaction
None3,045 (55.6%)
Unknown425 (7.8%)
Required2,002 (36.6%)
Privileges Required
Low1,133 (20.7%)
High334 (6.1%)
None3,580 (65.4%)
Unknown425 (7.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (5472 CVEs).

CISA KEV
85 CVEs
1.6% of CVEs· Bottom 1%
Metasploit
54 CVEs
1.0% of CVEs· Bottom 1%
Nuclei
54 CVEs
1.0% of CVEs· Bottom 1%
ExploitDB
93 CVEs
1.7% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fedora Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fedora Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fedora Project's Products

View all 73 CNAs →

Top CWEs