Known vulnerabilities in Fedora

Software: Fedora
Software CPE: cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:*
Total vulnerabilities: 13555
Public exploits: 703
Known exploited (KEV): 180
Highest CVSSv4 Score: 9.5

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Fedora Fedora is affected by 13555 known vulnerabilities: 104 critical, 3587 high, 5316 medium, 4547 low Critical High Medium Low

Vulnerabilities (13555)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU151796 - Use of Incorrectly-Resolved Name or Reference
CVE-2026-95275
CWE-706 Low
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151787 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2026-95288
CWE-451 Low
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151779 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2026-95279
CWE-451 Low
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151777 - Incorrect Authorization
CVE-2026-95292
CWE-863 Low
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151773 - Missing Authorization
CVE-2026-95278
CWE-862 Low
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151772 - Missing Authorization
CVE-2026-95285
CWE-862 Low
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151766 - Incorrect Authorization
CVE-2026-95289
CWE-863 Low
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151757 - Missing Authorization
CVE-2026-95290
CWE-862 Low
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151748 - Improper input validation
CVE-2026-95276
CWE-20 Low
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151725 - Missing Authorization
CVE-2026-95287
CWE-862 Low
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151720 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-95280
CWE-362 High
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151717 - Type confusion
CVE-2026-95286
CWE-843 High
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151712 - Use After Free
CVE-2026-95277
CWE-416 High
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151710 - Use After Free
CVE-2026-95282
CWE-416 High
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151709 - Improper Encoding or Escaping of Output
CVE-2026-95274
CWE-116 Low
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151707 - Memory corruption
CVE-2026-95283
CWE-119 High
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151701 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2026-95291
CWE-451 Low
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151695 - Memory corruption
CVE-2026-95284
CWE-119 High
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU151692 - Memory corruption
CVE-2026-95281
CWE-119 High
No
No
- 23.09.2026 SB2026092328
SB20260925244
SB20260925245
and 5 more
#VU144176 - Insufficient Verification of Data Authenticity
CVE-2026-56865
CWE-345 High
No
No
- 18.08.2026 SB2026081856
SB20260925263


Showing elements 1 - 20 out of 13555