Bootstrap Os
Vendor:
First CVE: Oct 21, 2019 · Active for 6 years
56
Total CVEs
More Total CVEs than 98% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
5.4%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Bootstrap Os over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 21, 2019
6 years ago
Most Recent CVE
Apr 15, 2025
465 days ago
CVE Severity & Scoring
Bootstrap Os56 CVEs
13%
45%
36%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local16 (28.6%)
Network40 (71.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (62.5%)
High21 (37.5%)
Unknown0 (0.0%)
User Interaction
None44 (78.6%)
Unknown0 (0.0%)
Required12 (21.4%)
Privileges Required
Low14 (25.0%)
High3 (5.4%)
None39 (69.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (56 CVEs).
56 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-24813CRITICAL Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau | Mar 10, 2025 | 9.8 | 99 | YES | YES |
CVE-2023-4911HIGH A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to us | Oct 3, 2023 | 7.8 | 98 | YES | YES |
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
CVE-2022-0492HIGH A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the | Mar 3, 2022 | 7.8 | 79 | YES | YES |
CVE-2022-2068HIGH In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to | Jun 21, 2022 | 7.3 | 76 | NO | NO |
CVE-2023-50868HIGH The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA- | Feb 14, 2024 | 7.5 | 72 | NO | NO |
CVE-2024-6119HIGH Issue summary: Applications performing certificate name checks (e.g., TLS
clients checking server certificates) may attempt to read an invalid memory
address resulting in abnormal | Sep 3, 2024 | 7.5 | 62 | NO | NO |
CVE-2024-50379CRITICAL Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is | Dec 17, 2024 | 9.8 | 58 | NO | NO |
CVE-2024-2398HIGH When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts t | Mar 27, 2024 | 8.6 | 46 | NO | NO |
CVE-2022-32206MEDIUM curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number o | Jul 7, 2022 | 6.5 | 38 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (56 CVEs).
CISA KEV
3 CVEs
5.4% of CVEs· 97th percentile
Metasploit
3 CVEs
5.4% of CVEs· 97th percentile
Nuclei
2 CVEs
3.6% of CVEs· 97th percentile
ExploitDB
3 CVEs
5.4% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (56 CVEs).
Media Mentions
Signals from CVEs in this product scope (56 CVEs).
Top CNAs Publishing CVEs For Bootstrap Os
Top CWEs
Versions
No cataloged versions.