fedora
CVE Numbering Authority
Latest CVE published
Overview
fedora is a CVE Numbering Authority that has published 281 CVE records since 2017. It is currently classified as active, with 124 CVEs published in the last two years. Its CVE data quality is graded F (54.4% overall completeness).
Among the 370 CNAs tracked here, fedora ranks #71 by CVE volume and reports more complete records than 10% of all CNAs.
Data quality report card
How complete and consistent fedora's CVE records are, scored across vendor, product, CVSS, and CWE coverage.
A CVE record only requires a description to be published. “Completeness” measures how often fedora also fills in the optional — but extremely useful — fields that make a vulnerability actually actionable: the affected vendor and product, a CVSS severity score, and a CWE weakness type. A higher score means more of this CNA’s CVEs include those details, so defenders spend less time enriching records by hand.
Report card grade
54.4%
Overall score
What these scores mean
- Vendor completeness
- The share of this CNA's CVEs that name an affected vendor.
- Product completeness
- The share that name a specific affected product.
- CVSS completeness
- The share that include a CVSS severity score.
- CWE completeness
- The share mapped to a CWE weakness type.
- Update rate
- How often this CNA revises CVE records after first publishing them.
- Vendor diversity
- How many distinct vendors this CNA publishes CVEs for.
Severity and exploitation
How the CVSS severity of fedora's published CVEs breaks down, and how many are known to be exploited in the wild.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of fedora's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Common weakness types
The CWE weakness categories fedora most often assigns to its CVEs. Follow any weakness to its full explanation.
- CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')35 CVEs
- CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer25 CVEs
- CWE-200Exposure of Sensitive Information to an Unauthorized Actor18 CVEs
- CWE-125Out-of-bounds Read14 CVEs
- CWE-94Improper Control of Generation of Code ('Code Injection')13 CVEs
- CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')12 CVEs
- CWE-863Incorrect Authorization12 CVEs
- CWE-352Cross-Site Request Forgery (CSRF)11 CVEs
Publishing activity by year
How many CVEs fedora has published each year.
Top vendors
The vendors fedora publishes the most CVEs for.
Top products
The products fedora publishes the most CVEs for.
- Moodle162 CVEs
- moodle/moodle157 CVEs
- Fedora76 CVEs
- Red Hat Enterprise Linux 822 CVEs
- Extra Packages for Enterprise Linux21 CVEs
- Red Hat Enterprise Linux 921 CVEs
- enterprise linux18 CVEs
- Red Hat Enterprise Linux 718 CVEs
Latest CVEs
The most recent CVEs assigned by fedora.
- CVE-2026-77652CWE-122
Dia: dia: heap buffer overflow in wpg colormap parser via out-of-bounds palette index
High · CVSS 7.8EPSS 0.2%2026-08-26 - CVE-2026-77658CWE-121
Dia: dia: stack buffer overflow in bus object via unvalidated handle count in project files
High · CVSS 7.8EPSS 0.1%2026-08-26 - CVE-2026-18487CWE-451
Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()
Medium · CVSS 5.4EPSS 0.3%2026-08-06 - CVE-2026-3842CWE-787
Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write
High · CVSS 7.8EPSS 0.2%2026-07-16 - CVE-2026-3195CWE-122
Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)
High · CVSS 7.4EPSS 0.2%2026-06-19 - CVE-2026-3196CWE-190
Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
Medium · CVSS 5.5EPSS 0.1%2026-06-19 - CVE-2026-1767CWE-805
Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leading to denial of service or information disclosure via malformed mp3 id3 tags
High · CVSS 8.1EPSS 0.2%2026-06-16 - CVE-2026-1766CWE-805
Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and information disclosure via malformed mp3 files.
Medium · CVSS 6.1EPSS 0.2%2026-06-16 - CVE-2026-1765CWE-125
Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and potential information disclosure via crafted mp3 files
Medium · CVSS 5.6EPSS 0.1%2026-06-16 - CVE-2026-1764CWE-125
Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leads to denial of service or information disclosure when parsing mp3 files
Medium · CVSS 5.6EPSS 0.2%2026-06-16 - CVE-2026-0708CWE-125
Libucl: libucl: denial of service via embedded null byte in ucl input
High · CVSS 8.3EPSS 0.4%2026-03-17 - CVE-2026-26047CWE-400
Moodle: moodle: uncontrolled resource consumption in tex formula editor leading to denial of service
Medium · CVSS 6.5EPSS 0.4%2026-02-21
Track new fedora CVEs as they are published and get AI-written analysis and remediation guidance.
Monitor fedora CVEsOther CNAs
Compare data quality across other CVE Numbering Authorities.
Frequently asked questions
Common questions about the fedora CNA.
- What is the fedora CNA?
- fedora is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 281 CVE records since 2017.
- How many CVEs has fedora published?
- fedora has published 281 CVE records, including 124 in the last two years.
- What is fedora's CVE data quality grade?
- RadicalNotion.AI grades fedora's CVE data quality as F, with an overall completeness score of 54.4%. This reflects how consistently its CVE records include vendor (17.4%), product (54.4%), CVSS (47.7%), and CWE (98.2%) information.
- What products does fedora publish CVEs for?
- fedora most frequently publishes CVEs for Moodle, moodle/moodle, Fedora, Red Hat Enterprise Linux 8, Extra Packages for Enterprise Linux.
- Which vendors does fedora cover?
- fedora publishes CVEs across 18 distinct vendors, most often Moodle, Fedora Project, Red Hat, Microsoft, debian.
- Is fedora actively publishing CVEs?
- fedora is currently active, based on 124 CVEs in the last two years.
- What is the average severity of fedora's CVEs?
- The average CVSS base score across fedora's scored CVEs is 6.1.
- How many critical CVEs has fedora published?
- fedora has published 28 critical-severity CVEs and 109 high-severity CVEs.
- Are any of fedora's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- No. None of fedora's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- What are the most common weakness types in fedora's CVEs?
- fedora's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), CWE-125 (Out-of-bounds Read).
- How does fedora rank among CNAs?
- By total CVE volume, fedora ranks #71 of 370 CNAs, and it reports more complete CVE records than 10% of all CNAs.
References
- Official CVE.org list of CNA partners (opens in a new tab)
- Learn: What is a CNA?
- CWE directory: the weakness types this CNA maps its CVEs to
CNA report-card grades are computed by RadicalNotion.AI from published CVE records. CVE data is sourced from the CVE Program.
Track fedora CVEs
Monitor new vulnerabilities as this CNA publishes them, with AI-written analysis and remediation guidance.