Systemd
Vendor:
First CVE: Oct 3, 2013 · Active for 12 years
55
Total CVEs
More Total CVEs than 98% of tracked products
4.6
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Systemd over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 3, 2013
12 years ago
Most Recent CVE
Apr 10, 2026
105 days ago
CVE Severity & Scoring
Systemd55 CVEs
53%
33%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local33 (60.0%)
Network12 (21.8%)
Unknown5 (9.1%)
Physical3 (5.5%)
Adjacent Network2 (3.6%)
Attack Complexity
Low40 (72.7%)
High10 (18.2%)
Unknown5 (9.1%)
User Interaction
None46 (83.6%)
Unknown5 (9.1%)
Required4 (7.3%)
Privileges Required
Low32 (58.2%)
High1 (1.8%)
None17 (30.9%)
Unknown5 (9.1%)
Top CVEs
Signals from CVEs in this product scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9445HIGH In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a | Jun 28, 2017 | 7.5 | 56 | NO | NO |
CVE-2018-15686HIGH A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence s | Oct 26, 2018 | 7.8 | 38 | NO | YES |
CVE-2017-15908HIGH In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function | Oct 26, 2017 | 7.5 | 37 | NO | NO |
CVE-2019-3844HIGH It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by | Apr 26, 2019 | 7.8 | 36 | NO | YES |
CVE-2019-3843HIGH It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the s | Apr 26, 2019 | 7.8 | 36 | NO | YES |
CVE-2017-18078HIGH systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows lo | Jan 29, 2018 | 7.8 | 35 | NO | YES |
CVE-2019-3842HIGH In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in som | Apr 9, 2019 | 7.0 | 34 | NO | YES |
CVE-2017-1000082CRITICAL systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user inte | Jul 7, 2017 | 9.8 | 34 | NO | NO |
CVE-2018-15687HIGH A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and inc | Oct 26, 2018 | 7.0 | 33 | NO | YES |
CVE-2016-10156HIGH A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their pri | Jan 23, 2017 | 7.8 | 33 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (55 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
12.7% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (55 CVEs).
Media Mentions
Signals from CVEs in this product scope (55 CVEs).
Top CNAs Publishing CVEs For Systemd
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9 | 1 | 6.3 | 0.4% | 0 | 0 |
| 8 | 1 | 6.3 | 0.4% | 0 | 0 |
| 7 | 1 | 6.3 | 0.4% | 0 | 0 |
| 6 | 1 | 6.3 | 0.4% | 0 | 0 |
| 5 | 1 | 6.3 | 0.4% | 0 | 0 |
| 4 | 1 | 6.3 | 0.4% | 0 | 0 |
| 37 | 1 | 5.5 | 0.4% | 0 | 0 |
| 36 | 1 | 6.3 | 0.4% | 0 | 0 |
| 35 | 1 | 6.3 | 0.4% | 0 | 0 |
| 34 | 1 | 6.3 | 0.4% | 0 | 0 |
| 33 | 1 | 6.3 | 0.4% | 0 | 0 |
| 32 | 1 | 6.3 | 0.4% | 0 | 0 |
| 31 | 1 | 6.3 | 0.4% | 0 | 0 |
| 30 | 1 | 6.3 | 0.4% | 0 | 0 |
| 3 | 1 | 6.3 | 0.4% | 0 | 0 |
| 29 | 1 | 6.3 | 0.4% | 0 | 0 |
| 28 | 1 | 6.3 | 0.4% | 0 | 0 |
| 27 | 1 | 6.3 | 0.4% | 0 | 0 |
| 260 | 1 | 5.5 | 0.2% | 0 | 0 |
| 26 | 1 | 6.3 | 0.4% | 0 | 0 |