Known vulnerabilities in Fedora 40

Software: Fedora
Version: 40
Software CPE: cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:*
Total vulnerabilities: 1148
Public exploits: 68
Known exploited (KEV): 18
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Fedora version 40 Fedora 40 is affected by 1148 vulnerabilities: 14 critical, 368 high, 449 medium, 317 low Critical High Medium Low

Vulnerabilities (1148)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121635 - Incorrect Authorization
CVE-2025-0781
CWE-863 High
No
No
- 16.01.2026 SB20260116119
SB20260116121
SB20260116122
and 1 more
#VU121008 - Insecure Automated Optimizations
CVE-2023-52971
CWE-1038 Low
No
No
- 07.01.2026 SB2025122915
SB2026010703
SB2026010704
and 5 more
#VU120623 - Insecure Automated Optimizations
CVE-2023-52970
CWE-1038 Low
No
No
- 29.12.2025 SB2025122915
SB2025122918
SB2025122926
and 12 more
#VU120622 - Insecure Automated Optimizations
CVE-2023-52969
CWE-1038 Low
No
No
- 29.12.2025 SB2025122915
SB2025122918
SB2025122920
and 16 more
#VU112886 - Off-by-one Error
CVE-2025-47711
CWE-193 Medium
No
No
- 14.07.2025 SB2025071451
SB2025071454
SB2025071455
and 8 more
#VU112885 - Reachable Assertion
CVE-2025-47712
CWE-617 Medium
No
No
- 14.07.2025 SB2025071451
SB2025071454
SB2025071455
and 8 more
#VU112026 - Asymmetric Resource Consumption (Amplification)
CVE-2025-25186
CWE-405 Medium
No
No
- 27.06.2025 SB2025062740
SB2025062741
SB2025062742
and 7 more
#VU111254 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-46337
CWE-89 High
No
No
- 18.06.2025 SB2025061805
SB2025061811
SB2025061812
and 4 more
#VU109941 - Resource exhaustion
CVE-2025-32907
CWE-400 Medium
No
No
- 29.05.2025 SB2025052993
SB2025052994
SB2025052995
and 27 more
#VU109939 - NULL Pointer Dereference
CVE-2025-32909
CWE-476 Low
No
No
- 29.05.2025 SB2025052718
SB2025052994
SB2025052995
and 14 more
#VU109936 - Use After Free
CVE-2025-32911
CWE-416 High
No
No
- 29.05.2025 SB2025052992
SB2025052997
SB2025052998
and 33 more
#VU109935 - NULL Pointer Dereference
CVE-2025-32910
CWE-476 Low
No
No
- 29.05.2025 SB2025052992
SB2025052997
SB2025052998
and 11 more
#VU109931 - Buffer over-read
CVE-2025-32050
CWE-126 Medium
No
No
- 29.05.2025 SB2024111329
SB2025052980
SB2025052994
and 28 more
#VU109929 - Buffer over-read
CVE-2025-32052
CWE-126 Medium
No
No
- 29.05.2025 SB2024111329
SB2025052980
SB2025052994
and 32 more
#VU109927 - Buffer over-read
CVE-2025-32053
CWE-126 Medium
No
No
- 29.05.2025 SB2024111329
SB2025052980
SB2025052994
and 29 more
#VU109838 - NULL Pointer Dereference
CVE-2025-32913
CWE-476 High
No
No
- 27.05.2025 SB2025052718
SB2025052723
SB2025052997
and 33 more
#VU109834 - Out-of-bounds read
CVE-2025-32906
CWE-125 Medium
No
No
- 27.05.2025 SB2025052715
SB2025052723
SB2025052994
and 37 more
#VU108913 - Stack-based buffer overflow
CVE-2025-47256
CWE-121 High
Public exploit available
No
- 12.05.2025 SB2025051219
SB2025051222
SB2025051223
and 2 more
#VU105106 - Improper input validation
CVE-2025-27219
CWE-20 Medium
No
No
- 27.02.2025 SB20250227242
SB2025030761
SB2025031451
and 15 more
#VU105105 - Exposure of sensitive information to an unauthorized actor
CVE-2025-27221
CWE-200 Medium
No
No
- 27.02.2025 SB20250227241
SB2025030761
SB2025031451
and 16 more


Showing elements 1 - 20 out of 1148