Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Linuxfoundation

First CVE: Jul 29, 2011Active for: 15 yearsTotal CVEs: 551
54.9
VTI Score
TOP TARGET

The Linux Foundation's vulnerability footprint spans a diverse portfolio of foundational and emerging open-source projects, including embedded systems frameworks (Yocto), machine-learning libraries (PyTorch), cryptographic initiatives (Everest), cloud-native infrastructure (NATS Server, Harbor), and other widely adopted tools, representing a significant presence in the software supply chain. Vulnerabilities affecting the vendor's projects skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the memory-safety and access-control demands of systems and infrastructure-layer software. The exposure recurs across these varied products through weakness classes including out-of-bounds reads and writes, path-traversal conditions, and authorization flaws, patterns characteristic of C and systems-code components that handle untrusted input or manage access to system resources. Defenders should monitor this vendor's project advisories broadly, as critical fixes often require coordinated patching across dependent systems; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
551
Total CVEs
More Total CVEs than 100% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Linuxfoundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 2011
14 years ago
Most Recent CVE
Jul 10, 2026
14 days ago

Products(111 total)

Top CVEs

Signals from CVEs in this vendor scope (551 CVEs).

551 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-5736HIGH
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi
Feb 11, 20198.691NOYES
CVE-2026-45321CRITICAL
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated
May 12, 20269.679YESNO
CVE-2023-27584CRITICAL
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project.
Sep 19, 20249.861NOYES
CVE-2024-21626HIGH
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker
Jan 31, 20248.654NOYES
CVE-2021-23450CRITICAL
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
Dec 17, 20219.851NONO
CVE-2022-46770HIGH
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafte
Dec 7, 20227.547NOYES
CVE-2019-16097MEDIUM
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend a
Sep 8, 20196.546NOYES
CVE-2026-50195CRITICAL
containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the
Jul 1, 20269.944NONO
CVE-2026-53492CRITICAL
containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations f
Jul 1, 20269.642NONO
CVE-2026-53488HIGH
containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instructio
Jul 1, 20268.841NONO
View all 551 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products551 CVEs
50%
37%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local162 (29.4%)
Network326 (59.2%)
Unknown13 (2.4%)
Physical16 (2.9%)
Adjacent Network34 (6.2%)
Attack Complexity
Low486 (88.2%)
High52 (9.4%)
Unknown13 (2.4%)
User Interaction
None466 (84.6%)
Unknown13 (2.4%)
Required72 (13.1%)
Privileges Required
Low158 (28.7%)
High96 (17.4%)
None284 (51.5%)
Unknown13 (2.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (551 CVEs).

CISA KEV
1 CVE
0.2% of CVEs· 99th percentile
Metasploit
3 CVEs
0.5% of CVEs· 97th percentile
Nuclei
3 CVEs
0.5% of CVEs· 95th percentile
ExploitDB
2 CVEs
0.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Linuxfoundation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Linuxfoundation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Linuxfoundation's Products

View all 19 CNAs →

Top CWEs