Fedora

Vendor:

First CVE: Jan 30, 2007 · Active for 19 years

5,391
Total CVEs
More Total CVEs than 100% of tracked products
283.7
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
1.6%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Fedora over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2007
19 years ago
Most Recent CVE
Jun 13, 2026
43 days ago

CVE Severity & Scoring

Fedora5,391 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local1,350 (25.0%)
Network3,595 (66.7%)
Unknown381 (7.1%)
Physical29 (0.5%)
Adjacent Network36 (0.7%)
Attack Complexity
Low4,513 (83.7%)
High497 (9.2%)
Unknown381 (7.1%)
User Interaction
None3,011 (55.9%)
Unknown381 (7.1%)
Required1,999 (37.1%)
Privileges Required
Low1,123 (20.8%)
High330 (6.1%)
None3,557 (66.0%)
Unknown381 (7.1%)

Top CVEs

Signals from CVEs in this product scope (5391 CVEs).

5,391 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows m
Jun 9, 20249.899YESYES
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori
Oct 7, 20219.899YESYES
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con
Oct 5, 20219.899YESYES
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc
Aug 17, 202010.099YESYES
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP sessio
Jan 29, 20209.899YESYES
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrar
Mar 27, 20197.599YESYES
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform
Apr 7, 20147.599YESYES

Exploit Exposure

Signals from CVEs in this product scope (5391 CVEs).

CISA KEV
85 CVEs
1.6% of CVEs· 96th percentile
Metasploit
54 CVEs
1.0% of CVEs· 96th percentile
Nuclei
54 CVEs
1.0% of CVEs· 96th percentile
ExploitDB
91 CVEs
1.7% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (5391 CVEs).

Media Mentions

Signals from CVEs in this product scope (5391 CVEs).

Top CNAs Publishing CVEs For Fedora

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9336.87.9%03
8306.76.0%01
7206.48.3%01
4446.90.1%00
4346.90.1%00
4115.50.3%00
402447.44.8%64
394927.15.4%2010
386366.95.0%2010
376957.04.3%159
367077.13.9%44
351,0967.26.1%2025
341,1797.16.6%2530
331,2077.05.6%2826
329716.85.9%2026
318686.95.7%1026
307287.16.5%722
293987.16.4%410
281057.46.7%14
27126.922.7%01