Fedora
Vendor:
First CVE: Jan 30, 2007 · Active for 19 years
5,391
Total CVEs
More Total CVEs than 100% of tracked products
283.7
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
1.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Fedora over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2007
19 years ago
Most Recent CVE
Jun 13, 2026
43 days ago
CVE Severity & Scoring
Fedora5,391 CVEs
43%
45%
9%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1,350 (25.0%)
Network3,595 (66.7%)
Unknown381 (7.1%)
Physical29 (0.5%)
Adjacent Network36 (0.7%)
Attack Complexity
Low4,513 (83.7%)
High497 (9.2%)
Unknown381 (7.1%)
User Interaction
None3,011 (55.9%)
Unknown381 (7.1%)
Required1,999 (37.1%)
Privileges Required
Low1,123 (20.8%)
High330 (6.1%)
None3,557 (66.0%)
Unknown381 (7.1%)
Top CVEs
Signals from CVEs in this product scope (5391 CVEs).
5,391 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4577CRITICAL In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows m | Jun 9, 2024 | 9.8 | 99 | YES | YES |
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2021-42013CRITICAL It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directori | Oct 7, 2021 | 9.8 | 99 | YES | YES |
CVE-2021-41773CRITICAL A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories con | Oct 5, 2021 | 9.8 | 99 | YES | YES |
CVE-2021-3156HIGH Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg | Jan 26, 2021 | 7.8 | 99 | YES | YES |
CVE-2020-1472CRITICAL An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc | Aug 17, 2020 | 10.0 | 99 | YES | YES |
CVE-2020-1938CRITICAL When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e | Feb 24, 2020 | 9.8 | 99 | YES | YES |
CVE-2020-7247CRITICAL smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP sessio | Jan 29, 2020 | 9.8 | 99 | YES | YES |
CVE-2019-5418HIGH There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrar | Mar 27, 2019 | 7.5 | 99 | YES | YES |
CVE-2014-0160HIGH The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform | Apr 7, 2014 | 7.5 | 99 | YES | YES |
Exploit Exposure
Signals from CVEs in this product scope (5391 CVEs).
CISA KEV
85 CVEs
1.6% of CVEs· 96th percentile
Metasploit
54 CVEs
1.0% of CVEs· 96th percentile
Nuclei
54 CVEs
1.0% of CVEs· 96th percentile
ExploitDB
91 CVEs
1.7% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (5391 CVEs).
Media Mentions
Signals from CVEs in this product scope (5391 CVEs).
Top CNAs Publishing CVEs For Fedora
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9 | 33 | 6.8 | 7.9% | 0 | 3 |
| 8 | 30 | 6.7 | 6.0% | 0 | 1 |
| 7 | 20 | 6.4 | 8.3% | 0 | 1 |
| 44 | 4 | 6.9 | 0.1% | 0 | 0 |
| 43 | 4 | 6.9 | 0.1% | 0 | 0 |
| 41 | 1 | 5.5 | 0.3% | 0 | 0 |
| 40 | 244 | 7.4 | 4.8% | 6 | 4 |
| 39 | 492 | 7.1 | 5.4% | 20 | 10 |
| 38 | 636 | 6.9 | 5.0% | 20 | 10 |
| 37 | 695 | 7.0 | 4.3% | 15 | 9 |
| 36 | 707 | 7.1 | 3.9% | 4 | 4 |
| 35 | 1,096 | 7.2 | 6.1% | 20 | 25 |
| 34 | 1,179 | 7.1 | 6.6% | 25 | 30 |
| 33 | 1,207 | 7.0 | 5.6% | 28 | 26 |
| 32 | 971 | 6.8 | 5.9% | 20 | 26 |
| 31 | 868 | 6.9 | 5.7% | 10 | 26 |
| 30 | 728 | 7.1 | 6.5% | 7 | 22 |
| 29 | 398 | 7.1 | 6.4% | 4 | 10 |
| 28 | 105 | 7.4 | 6.7% | 1 | 4 |
| 27 | 12 | 6.9 | 22.7% | 0 | 1 |