Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could exploit CVE-2026-2332 to perform HTTP request smuggling against the embedded Jetty server, potentially gaining unauthorized access to Kafka data or triggering denial of service. CVE-2019-1010023 requires local access to run ldd on a malicious ELF, but could lead to code execution under those conditions. Restricting network access to the Kafka management interfaces and disabling unused modules like the Jetty HTTP connector would mitigate the most critical attack vectors.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-2332 | CRITICAL9.1 | org.eclipse.jetty:jetty-http 9.4.48.v20220622 fixed in 12.1.7, 12.0.33 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010023 | HIGH8.8 | libc-bin 2.31-13+deb11u5 No fix yet | 3.1% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010023 | HIGH8.8 | libc6 2.31-13+deb11u5 No fix yet | 3.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-2650 | HIGH8.45 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1n-0+deb11u5 | 73.5% Actively Exploited | Directly Exposed |
| CVE-2025-32988 | HIGH8.2 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u8 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-45447 | HIGH8.1 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u8 | 2.7% Low-Moderate Risk | Directly Exposed |
| CVE-2022-1304 | HIGH7.8 | libcom-err2 1.46.2-2 fixed in 1.46.2-2+deb11u1 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2017-7245 | HIGH7.8 | libpcre3 2:8.39-13 No fix yet | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2017-7246 | HIGH7.8 | libpcre3 2:8.39-13 No fix yet | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33845 | HIGH7.73 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u10 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-33599 | HIGH7.6 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u10 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33599 | HIGH7.6 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u10 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2018-20796 | HIGH7.5 | libc-bin 2.31-13+deb11u5 No fix yet | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2019-9192 | HIGH7.5 | libc-bin 2.31-13+deb11u5 No fix yet | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2018-20796 | HIGH7.5 | libc6 2.31-13+deb11u5 No fix yet | 5.8% Low-Moderate Risk | Directly Exposed |
| CVE-2019-9192 | HIGH7.5 | libc6 2.31-13+deb11u5 No fix yet | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2021-33560 | HIGH7.5 | libgcrypt20 1.8.7-6 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2018-6829 | HIGH7.5 | libgcrypt20 1.8.7-6 No fix yet | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2024-0553 | HIGH7.5 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u5 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-0567 | HIGH7.5 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u5 | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33846 | HIGH7.5 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u10 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42009 | HIGH7.5 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u10 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2018-5709 | HIGH7.5 | libgssapi-krb5-2 1.18.3-6+deb11u3 No fix yet | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-5709 | HIGH7.5 | libk5crypto3 1.18.3-6+deb11u3 No fix yet | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-5709 | HIGH7.5 | libkrb5-3 1.18.3-6+deb11u3 No fix yet | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2018-5709 | HIGH7.5 | libkrb5support0 1.18.3-6+deb11u3 No fix yet | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-2953 | HIGH7.5 | libldap-2.4-2 2.4.57+dfsg-3+deb11u1 No fix yet | 1.9% Low-Moderate Risk | Directly Exposed |
| CVE-2015-3276 | HIGH7.5 | libldap-2.4-2 2.4.57+dfsg-3+deb11u1 No fix yet | 5.3% Low-Moderate Risk | Directly Exposed |
| CVE-2017-17740 | HIGH7.5 | libldap-2.4-2 2.4.57+dfsg-3+deb11u1 No fix yet | 7.0% Low-Moderate Risk | Directly Exposed |
| CVE-2017-11164 | HIGH7.5 | libpcre3 2:8.39-13 No fix yet | 3.1% Low-Moderate Risk | Directly Exposed |
| CVE-2019-20838 | HIGH7.5 | libpcre3 2:8.39-13 No fix yet | 2.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-0464 | HIGH7.5 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1n-0+deb11u5 | 3.7% Low-Moderate Risk | Directly Exposed |
| CVE-2022-4899 | HIGH7.5 | libzstd1 1.4.8+dfsg-2.1 No fix yet | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34455 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.8.4 fixed in 1.1.10.1 | 1.8% Low-Moderate Risk | Directly Exposed |
| CVE-2023-43642 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.8.4 fixed in 1.1.10.4 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34453 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.8.4 fixed in 1.1.10.1 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34454 | HIGH7.5 | org.xerial.snappy:snappy-java 1.1.8.4 fixed in 1.1.10.1 | 1.5% Low-Moderate Risk | Directly Exposed |
| CVE-2025-27819 | HIGH7.48 | org.apache.kafka:kafka_2.12 3.3.2 fixed in 3.4.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-67030 | HIGH7.48 | org.codehaus.plexus:plexus-utils 3.3.0 fixed in 4.0.3, 3.6.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-37371 | HIGH7.28 | libgssapi-krb5-2 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u5 | 1.9% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-37371 | HIGH7.28 | libk5crypto3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u5 | 1.9% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-37371 | HIGH7.28 | libkrb5-3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u5 | 1.9% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-37371 | HIGH7.28 | libkrb5support0 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u5 | 1.9% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2025-32990 | MEDIUM6.97 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u8 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-42013 | MEDIUM6.97 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u10 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5260 | MEDIUM6.97 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u10 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-28182 | MEDIUM6.89 | libnghttp2-14 1.43.0-1 fixed in 1.43.0-1+deb11u2 | 85.0% Actively Exploited | Directly Exposed |
| CVE-2026-0861 | MEDIUM6.88 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0861 | MEDIUM6.88 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.13.4.2 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.13.4.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-44249 | MEDIUM6.88 | io.netty:netty-handler 4.1.78.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-27818 | MEDIUM6.8 | org.apache.kafka:kafka_2.12 3.3.2 fixed in 3.9.1 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-29111 | MEDIUM6.63 | libsystemd0 247.3-7+deb11u1 fixed in 247.3-7+deb11u8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-29111 | MEDIUM6.63 | libudev1 247.3-7+deb11u1 fixed in 247.3-7+deb11u8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-36054 | MEDIUM6.5 | libgssapi-krb5-2 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u4 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-36054 | MEDIUM6.5 | libk5crypto3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u4 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-36054 | MEDIUM6.5 | libkrb5-3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u4 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-36054 | MEDIUM6.5 | libkrb5support0 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u4 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-34462 | MEDIUM6.5 | io.netty:netty-handler 4.1.78.Final fixed in 4.1.94.Final | 2.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-8184 | MEDIUM6.5 | org.eclipse.jetty:jetty-server 9.4.48.v20220622 fixed in 12.0.9, 10.0.24, 11.0.24, 9.4.56 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | libgssapi-krb5-2 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u5 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libgssapi-krb5-2 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libgssapi-krb5-2 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | libk5crypto3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u5 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libk5crypto3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libk5crypto3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | libkrb5-3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u5 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libkrb5-3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libkrb5-3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | libkrb5support0 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u5 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libkrb5support0 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libkrb5support0 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-27135 | MEDIUM6.38 | libnghttp2-14 1.43.0-1 fixed in 1.43.0-1+deb11u3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2022-41409 | MEDIUM6.38 | libpcre2-8-0 10.36-2+deb11u1 No fix yet | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28388 | MEDIUM6.38 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u7 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-28389 | MEDIUM6.38 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u7 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-28390 | MEDIUM6.38 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u7 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-52999 | MEDIUM6.38 | com.fasterxml.jackson.core:jackson-core 2.13.4 fixed in 2.15.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-50193 | MEDIUM6.38 | com.fasterxml.jackson.core:jackson-databind 2.13.4.2 fixed in 2.14.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42583 | MEDIUM6.38 | io.netty:netty-codec 4.1.78.Final fixed in 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-58057 | MEDIUM6.38 | io.netty:netty-codec 4.1.78.Final fixed in 4.1.125.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45416 | MEDIUM6.38 | io.netty:netty-handler 4.1.78.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-50010 | MEDIUM6.38 | io.netty:netty-handler 4.1.78.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31582 | MEDIUM6.38 | org.bitbucket.b_c:jose4j 0.7.9 fixed in 0.9.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-29371 | MEDIUM6.38 | org.bitbucket.b_c:jose4j 0.7.9 fixed in 0.9.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-51775 | MEDIUM6.38 | org.bitbucket.b_c:jose4j 0.7.9 fixed in 0.9.4 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2024-9823 | MEDIUM6.38 | org.eclipse.jetty:jetty-servlets 9.4.48.v20220622 fixed in 9.4.54, 10.0.18, 11.0.18 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-66566 | MEDIUM6.38 | org.lz4:lz4-java 1.8.0 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-3833 | MEDIUM6.29 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u10 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42011 | MEDIUM6.29 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u10 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-56128 | MEDIUM6.29 | org.apache.kafka:kafka_2.12 3.3.2 fixed in 3.7.2, 3.8.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-13009 | MEDIUM6.12 | org.eclipse.jetty:jetty-server 9.4.48.v20220622 fixed in 9.4.57.v20241219 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2020-13529 | MEDIUM6.1 | libsystemd0 247.3-7+deb11u1 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2020-13529 | MEDIUM6.1 | libudev1 247.3-7+deb11u1 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2026-54369 | MEDIUM6.03 | libacl1 2.2.53-10 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42012 | MEDIUM6.03 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u10 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-4802 | MEDIUM5.95 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u13 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-4802 | MEDIUM5.95 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u13 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2023-4806 | MEDIUM5.9 | libc-bin 2.31-13+deb11u5 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2023-4813 | MEDIUM5.9 | libc-bin 2.31-13+deb11u5 No fix yet | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2023-4806 | MEDIUM5.9 | libc6 2.31-13+deb11u5 No fix yet | 1.4% Low-Moderate Risk | Directly Exposed |
| CVE-2023-4813 | MEDIUM5.9 | libc6 2.31-13+deb11u5 No fix yet | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2024-2236 | MEDIUM5.9 | libgcrypt20 1.8.7-6 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5981 | MEDIUM5.9 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u4 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libgssapi-krb5-2 1.18.3-6+deb11u3 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libk5crypto3 1.18.3-6+deb11u3 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libkrb5-3 1.18.3-6+deb11u3 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-26461 | MEDIUM5.9 | libkrb5support0 1.18.3-6+deb11u3 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-5535 | MEDIUM5.9 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u2 | 5.6% Low-Moderate Risk | Directly Exposed |
| CVE-2025-13151 | MEDIUM5.9 | libtasn1-6 4.16.0-2+deb11u1 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-22185 | MEDIUM5.78 | libldap-2.4-2 2.4.57+dfsg-3+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-35554 | MEDIUM5.78 | org.apache.kafka:kafka-clients 3.3.2 fixed in 3.9.2, 4.0.2, 4.1.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4105 | MEDIUM5.7 | libsystemd0 247.3-7+deb11u1 fixed in 247.3-7+deb11u8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-4105 | MEDIUM5.7 | libudev1 247.3-7+deb11u1 fixed in 247.3-7+deb11u8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42014 | MEDIUM5.61 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u10 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2024-23944 | MEDIUM5.61 | org.apache.zookeeper:zookeeper 3.6.3 fixed in 3.8.4, 3.9.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u4 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2024-4741 | MEDIUM5.6 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u2 | 2.9% Low-Moderate Risk | Directly Exposed |
| CVE-2011-3389 | MEDIUM5.59 | libgnutls30 3.7.1-5+deb11u3 No fix yet | 73.3% Actively Exploited | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc-bin 2.31-13+deb11u5 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc6 2.31-13+deb11u5 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-6395 | MEDIUM5.52 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | libgssapi-krb5-2 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | libk5crypto3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | libkrb5-3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | libkrb5support0 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-11143 | MEDIUM5.52 | org.eclipse.jetty:jetty-http 9.4.48.v20220622 fixed in 12.0.31, 12.1.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-12183 | MEDIUM5.52 | org.lz4:lz4-java 1.8.0 fixed in 1.8.1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-0727 | MEDIUM5.5 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u2 | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-40225 | MEDIUM5.44 | libsystemd0 247.3-7+deb11u1 fixed in 247.3-7+deb11u8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40226 | MEDIUM5.44 | libsystemd0 247.3-7+deb11u1 fixed in 247.3-7+deb11u8 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40225 | MEDIUM5.44 | libudev1 247.3-7+deb11u1 fixed in 247.3-7+deb11u8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40226 | MEDIUM5.44 | libudev1 247.3-7+deb11u1 fixed in 247.3-7+deb11u8 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54370 | MEDIUM5.35 | libacl1 2.2.53-10 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54371 | MEDIUM5.35 | libattr1 1:2.4.48-6 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2024-33600 | MEDIUM5.3 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u10 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010024 | MEDIUM5.3 | libc-bin 2.31-13+deb11u5 No fix yet | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010025 | MEDIUM5.3 | libc-bin 2.31-13+deb11u5 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33600 | MEDIUM5.3 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u10 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010024 | MEDIUM5.3 | libc6 2.31-13+deb11u5 No fix yet | 3.2% Low-Moderate Risk | Directly Exposed |
| CVE-2019-1010025 | MEDIUM5.3 | libc6 2.31-13+deb11u5 No fix yet | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2024-12243 | MEDIUM5.3 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u7 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2023-0465 | MEDIUM5.3 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1n-0+deb11u5 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2023-0466 | MEDIUM5.3 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1n-0+deb11u5 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2023-3446 | MEDIUM5.3 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1v-0~deb11u1 | 5.5% Low-Moderate Risk | Directly Exposed |
| CVE-2023-3817 | MEDIUM5.3 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1v-0~deb11u1 | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2023-5678 | MEDIUM5.3 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u2 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2024-12133 | MEDIUM5.3 | libtasn1-6 4.16.0-2+deb11u1 fixed in 4.16.0-2+deb11u2 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-31141 | MEDIUM5.3 | org.apache.kafka:kafka-clients 3.3.2 fixed in 3.7.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-40167 | MEDIUM5.3 | org.eclipse.jetty:jetty-http 9.4.48.v20220622 fixed in 9.4.52, 10.0.16, 11.0.16, 12.0.1 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-26048 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.4.48.v20220622 fixed in 9.4.51.v20230217, 10.0.14, 11.0.14 | 3.3% Low-Moderate Risk | Directly Exposed |
| CVE-2023-26049 | MEDIUM5.3 | org.eclipse.jetty:jetty-server 9.4.48.v20220622 fixed in 9.4.51.v20230217, 10.0.14, 11.0.14, 12.0.0.beta0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | libp11-kit0 0.23.22-1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libblkid1 2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libmount1 2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-14104 | MEDIUM5.18 | libuuid1 2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-2398 | MEDIUM5.17 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u12 | 36.1% High Exploitation Risk | Post-Exploit |
| CVE-2024-2398 | MEDIUM5.17 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u12 | 36.1% High Exploitation Risk | Post-Exploit |
| CVE-2023-2650 | MEDIUM5.07 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1n-0+deb11u5 | 73.5% Actively Exploited | Post-Exploit |
| CVE-2026-57432 | MEDIUM5.04 | perl-base 5.32.1-4+deb11u2 No fix yet | — | Post-Exploit |
| CVE-2026-5435 | MEDIUM5.02 | libc-bin 2.31-13+deb11u5 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15281 | MEDIUM5.02 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u14 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc6 2.31-13+deb11u5 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15281 | MEDIUM5.02 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u14 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | libgssapi-krb5-2 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libgssapi-krb5-2 1.18.3-6+deb11u3 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | libk5crypto3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libk5crypto3 1.18.3-6+deb11u3 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | libkrb5-3 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libkrb5-3 1.18.3-6+deb11u3 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-3576 | MEDIUM5.02 | libkrb5support0 1.18.3-6+deb11u3 fixed in 1.18.3-6+deb11u7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-26458 | MEDIUM5.02 | libkrb5support0 1.18.3-6+deb11u3 No fix yet | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-7008 | MEDIUM5.02 | libsystemd0 247.3-7+deb11u1 fixed in 247.3-7+deb11u6 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2023-7008 | MEDIUM5.02 | libudev1 247.3-7+deb11u1 fixed in 247.3-7+deb11u6 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-8376 | MEDIUM5 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-45447 | MEDIUM4.86 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u8 | 2.7% Low-Moderate Risk | Post-Exploit |
| CVE-2023-31484 | MEDIUM4.86 | perl-base 5.32.1-4+deb11u2 fixed in 5.32.1-4+deb11u4 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-31486 | MEDIUM4.86 | perl-base 5.32.1-4+deb11u2 No fix yet | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2511 | MEDIUM4.81 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u2 | 54.0% Actively Exploited | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libblkid1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-0395 | MEDIUM4.67 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u12 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-0395 | MEDIUM4.67 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u12 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libmount1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2017-16231 | MEDIUM4.67 | libpcre3 2:8.39-13 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-3821 | MEDIUM4.67 | libsystemd0 247.3-7+deb11u1 fixed in 247.3-7+deb11u2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-4415 | MEDIUM4.67 | libsystemd0 247.3-7+deb11u1 fixed in 247.3-7+deb11u2 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-3821 | MEDIUM4.67 | libudev1 247.3-7+deb11u1 fixed in 247.3-7+deb11u2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2022-4415 | MEDIUM4.67 | libudev1 247.3-7+deb11u1 fixed in 247.3-7+deb11u2 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-0563 | MEDIUM4.67 | libuuid1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.2.11.dfsg-2+deb11u2 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-47535 | MEDIUM4.67 | io.netty:netty-common 4.1.78.Final fixed in 4.1.115.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-25193 | MEDIUM4.67 | io.netty:netty-common 4.1.78.Final fixed in 4.1.118.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-23914 | MEDIUM4.64 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2023-23914 | MEDIUM4.64 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-7598 | MEDIUM4.64 | libssh2-1 1.9.0-2 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42496 | MEDIUM4.64 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-58055 | MEDIUM4.59 | libnghttp2-14 1.43.0-1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-38545 | MEDIUM4.58 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u10 | 78.5% Actively Exploited | Post-Exploit |
| CVE-2023-38545 | MEDIUM4.58 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u10 | 78.5% Actively Exploited | Post-Exploit |
| CVE-2022-42916 | MEDIUM4.5 | curl 7.74.0-1.3+deb11u5 No fix yet | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2022-42916 | MEDIUM4.5 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-0464 | MEDIUM4.5 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1n-0+deb11u5 | 3.7% Low-Moderate Risk | Post-Exploit |
| CVE-2026-13595 | MEDIUM4.5 | libblkid1 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libblkid1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0915 | MEDIUM4.5 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u14 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-0915 | MEDIUM4.5 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u14 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u14 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-28834 | MEDIUM4.5 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u6 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-14831 | MEDIUM4.5 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u9 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42015 | MEDIUM4.5 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u10 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34743 | MEDIUM4.5 | liblzma5 5.2.5-2.1~deb11u1 fixed in 5.2.5-2.1~deb11u2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-13595 | MEDIUM4.5 | libmount1 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libmount1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-13595 | MEDIUM4.5 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u8 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2023-31437 | MEDIUM4.5 | libsystemd0 247.3-7+deb11u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31438 | MEDIUM4.5 | libsystemd0 247.3-7+deb11u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31439 | MEDIUM4.5 | libsystemd0 247.3-7+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2023-31437 | MEDIUM4.5 | libudev1 247.3-7+deb11u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31438 | MEDIUM4.5 | libudev1 247.3-7+deb11u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2023-31439 | MEDIUM4.5 | libudev1 247.3-7+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-13595 | MEDIUM4.5 | libuuid1 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-3184 | MEDIUM4.5 | libuuid1 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.13.4.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.13.4.2 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-6763 | MEDIUM4.5 | org.eclipse.jetty:jetty-http 9.4.48.v20220622 fixed in 12.0.12 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2024-7264 | MEDIUM4.48 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u13 | 17.3% High Exploitation Risk | Post-Exploit |
| CVE-2024-7264 | MEDIUM4.48 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u13 | 17.3% High Exploitation Risk | Post-Exploit |
| CVE-2024-28085 | MEDIUM4.4 | libblkid1 2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-28085 | MEDIUM4.4 | libmount1 2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-28085 | MEDIUM4.4 | libsmartcols1 2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-28085 | MEDIUM4.4 | libuuid1 2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42250 | MEDIUM4.25 | libbz2-1.0 1.0.8-4 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc-bin 2.31-13+deb11u5 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc-bin 2.31-13+deb11u5 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc6 2.31-13+deb11u5 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc6 2.31-13+deb11u5 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-28835 | MEDIUM4.25 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libgssapi-krb5-2 1.18.3-6+deb11u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libk5crypto3 1.18.3-6+deb11u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libkrb5-3 1.18.3-6+deb11u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libkrb5support0 1.18.3-6+deb11u3 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM4.25 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-55200 | MEDIUM4.23 | libssh2-1 1.9.0-2 No fix yet | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2020-15719 | MEDIUM4.2 | libldap-2.4-2 2.4.57+dfsg-3+deb11u1 No fix yet | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2026-8286 | MEDIUM4.13 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-15079 | MEDIUM4.13 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8286 | MEDIUM4.13 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-15079 | MEDIUM4.13 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-28387 | MEDIUM4.13 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u7 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2024-2961 | MEDIUM4.12 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u9 | 88.3% Actively Exploited | Post-Exploit |
| CVE-2024-2961 | MEDIUM4.12 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u9 | 88.3% Actively Exploited | Post-Exploit |
| CVE-2023-4039 | MEDIUM4.08 | libgcc-s1 10.2.1-6 No fix yet | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2023-4039 | MEDIUM4.08 | libstdc++6 10.2.1-6 No fix yet | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2019-8457 | MEDIUM4.06 | libdb5.3 5.3.28+dfsg1-0.8 No fix yet | 45.4% High Exploitation Risk | Post-Exploit |
| CVE-2026-27456 | MEDIUM4 | libblkid1 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2017-14159 | MEDIUM4 | libldap-2.4-2 2.4.57+dfsg-3+deb11u1 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount1 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-4598 | MEDIUM4 | libsystemd0 247.3-7+deb11u1 fixed in 247.3-7+deb11u7 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-4598 | MEDIUM4 | libudev1 247.3-7+deb11u1 fixed in 247.3-7+deb11u7 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid1 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2010-4756 | MEDIUM4 | libc-bin 2.31-13+deb11u5 No fix yet | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33601 | MEDIUM4 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u10 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2010-4756 | MEDIUM4 | libc6 2.31-13+deb11u5 No fix yet | 2.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-33601 | MEDIUM4 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u10 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2022-3715 | LOW3.98 | bash 5.1-2+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2020-16156 | LOW3.98 | perl-base 5.32.1-4+deb11u2 fixed in 5.32.1-4+deb11u4 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2023-47038 | LOW3.98 | perl-base 5.32.1-4+deb11u2 fixed in 5.32.1-4+deb11u3 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-48962 | LOW3.98 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-31133 | LOW3.98 | github.com/opencontainers/runc v1.1.0 fixed in 1.2.8, 1.3.3, 1.4.0-rc.3 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2022-29162 | LOW3.98 | github.com/opencontainers/runc v1.1.0 fixed in 1.1.2 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-28642 | LOW3.98 | github.com/opencontainers/runc v1.1.0 fixed in 1.1.5 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2023-23916 | LOW3.9 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u7 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46218 | LOW3.9 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u11 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-9681 | LOW3.9 | curl 7.74.0-1.3+deb11u5 No fix yet | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-11856 | LOW3.9 | curl 7.74.0-1.3+deb11u5 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2021-22922 | LOW3.9 | curl 7.74.0-1.3+deb11u5 No fix yet | 4.3% Low-Moderate Risk | Post-Exploit |
| CVE-2023-23916 | LOW3.9 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u7 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46218 | LOW3.9 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u11 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-9681 | LOW3.9 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-11856 | LOW3.9 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2021-22922 | LOW3.9 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 4.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-5773 | LOW3.82 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-6276 | LOW3.82 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW3.82 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW3.82 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-41992 | LOW3.82 | gzip 1.10-4+deb11u1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-5773 | LOW3.82 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-6276 | LOW3.82 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW3.82 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW3.82 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2020-22218 | LOW3.82 | libssh2-1 1.9.0-2 fixed in 1.9.0-2+deb11u1 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-55199 | LOW3.82 | libssh2-1 1.9.0-2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69421 | LOW3.82 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-28388 | LOW3.82 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u7 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-28389 | LOW3.82 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u7 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-28390 | LOW3.82 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u7 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-42497 | LOW3.82 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9538 | LOW3.82 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-52565 | LOW3.82 | github.com/opencontainers/runc v1.1.0 fixed in 1.2.8, 1.3.3, 1.4.0-rc.3 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-52881 | LOW3.82 | github.com/opencontainers/runc v1.1.0 fixed in 1.2.8, 1.3.3, 1.4.0-rc.3 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-27817 | LOW3.79 | org.apache.kafka:kafka-clients 3.3.2 fixed in 3.9.1 | 62.4% Actively Exploited | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-69419 | LOW3.77 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2011-3374 | LOW3.7 | libapt-pkg6.0 2.2.4 No fix yet | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-9143 | LOW3.7 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u2 | 6.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.12.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.8.1 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2023-4911 | LOW3.65 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u7 | 81.4% Actively Exploited | Post-Exploit |
| CVE-2023-4911 | LOW3.65 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u7 | 81.4% Actively Exploited | Post-Exploit |
| CVE-2005-2541 | LOW3.6 | tar 1.34+dfsg-1 No fix yet | 4.0% Low-Moderate Risk | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gpgv 2.2.27-2+deb11u2 fixed in 2.2.27-2+deb11u3 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2023-27561 | LOW3.57 | github.com/opencontainers/runc v1.1.0 fixed in 1.1.5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-8058 | LOW3.57 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u14 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-8058 | LOW3.57 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u14 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-21626 | LOW3.56 | github.com/opencontainers/runc v1.1.0 fixed in 1.1.12 | 18.1% High Exploitation Risk | Post-Exploit |
| CVE-2023-27535 | LOW3.54 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u8 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27536 | LOW3.54 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u8 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-28321 | LOW3.54 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u9 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2023-28320 | LOW3.54 | curl 7.74.0-1.3+deb11u5 No fix yet | 2.7% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27535 | LOW3.54 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u8 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27536 | LOW3.54 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u8 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-28321 | LOW3.54 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u9 | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2023-28320 | LOW3.54 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 2.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-5535 | LOW3.54 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u2 | 5.6% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010022 | LOW3.53 | libc-bin 2.31-13+deb11u5 No fix yet | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2019-1010022 | LOW3.53 | libc6 2.31-13+deb11u5 No fix yet | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42010 | LOW3.53 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u10 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2023-45853 | LOW3.53 | zlib1g 1:1.2.11.dfsg-2+deb11u2 No fix yet | 2.9% Low-Moderate Risk | Post-Exploit |
| CVE-2023-44487 | LOW3.51 | libnghttp2-14 1.43.0-1 fixed in 1.43.0-1+deb11u1 | 100.0% Actively Exploited | Post-Exploit |
| CVE-2023-50387 | LOW3.51 | libsystemd0 247.3-7+deb11u1 fixed in 247.3-7+deb11u6 | 100.0% Actively Exploited | Post-Exploit |
| CVE-2023-50868 | LOW3.51 | libsystemd0 247.3-7+deb11u1 fixed in 247.3-7+deb11u6 | 81.7% Actively Exploited | Post-Exploit |
| CVE-2023-50387 | LOW3.51 | libudev1 247.3-7+deb11u1 fixed in 247.3-7+deb11u6 | 100.0% Actively Exploited | Post-Exploit |
| CVE-2023-50868 | LOW3.51 | libudev1 247.3-7+deb11u1 fixed in 247.3-7+deb11u6 | 81.7% Actively Exploited | Post-Exploit |
| CVE-2026-1965 | LOW3.47 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-1965 | LOW3.47 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2024-33602 | LOW3.4 | libc-bin 2.31-13+deb11u5 fixed in 2.31-13+deb11u10 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-33602 | LOW3.4 | libc6 2.31-13+deb11u5 fixed in 2.31-13+deb11u10 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-9820 | LOW3.4 | libgnutls30 3.7.1-5+deb11u3 fixed in 3.7.1-5+deb11u9 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl1.1 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-epoll 4.1.78.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | LOW3.36 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u4 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-4741 | LOW3.36 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u2 | 2.9% Low-Moderate Risk | Post-Exploit |
| CVE-2016-2781 | LOW3.31 | coreutils 8.32-4+b1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-23915 | LOW3.31 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2024-8096 | LOW3.31 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u14 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-3784 | LOW3.31 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6429 | LOW3.31 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-14524 | LOW3.31 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2023-23915 | LOW3.31 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2024-8096 | LOW3.31 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u14 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-3784 | LOW3.31 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6429 | LOW3.31 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-14524 | LOW3.31 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-15661 | LOW3.31 | libssh2-1 1.9.0-2 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-15649 | LOW3.31 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2023-27538 | LOW3.3 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u8 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27538 | LOW3.3 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u8 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2024-0727 | LOW3.3 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u2 | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2022-48303 | LOW3.3 | tar 1.34+dfsg-1 fixed in 1.34+dfsg-1+deb11u1 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-13221 | LOW3.28 | perl-base 5.32.1-4+deb11u2 No fix yet | — | Post-Exploit |
| CVE-2023-44981 | LOW3.28 | org.apache.zookeeper:zookeeper 3.6.3 fixed in 3.7.2, 3.8.3, 3.9.1 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2379 | LOW3.24 | curl 7.74.0-1.3+deb11u5 No fix yet | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-2379 | LOW3.24 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2026-5958 | LOW3.21 | sed 4.7-1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2023-25809 | LOW3.21 | github.com/opencontainers/runc v1.1.0 fixed in 1.1.5 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2023-46219 | LOW3.18 | curl 7.74.0-1.3+deb11u5 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2021-22923 | LOW3.18 | curl 7.74.0-1.3+deb11u5 No fix yet | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46219 | LOW3.18 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2021-22923 | LOW3.18 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 1.8% Low-Moderate Risk | Post-Exploit |
| CVE-2023-0465 | LOW3.18 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1n-0+deb11u5 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-0466 | LOW3.18 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1n-0+deb11u5 | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-3446 | LOW3.18 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1v-0~deb11u1 | 5.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-3817 | LOW3.18 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1v-0~deb11u1 | 2.6% Low-Moderate Risk | Post-Exploit |
| CVE-2023-5678 | LOW3.18 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u2 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27533 | LOW3.17 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u8 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27534 | LOW3.17 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u8 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27533 | LOW3.17 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u8 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2023-27534 | LOW3.17 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u8 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-14104 | LOW3.11 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-14104 | LOW3.11 | mount 2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-14104 | LOW3.11 | util-linux 2.36.1-8+deb11u1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2022-43551 | LOW3.1 | curl 7.74.0-1.3+deb11u5 No fix yet | 16.5% High Exploitation Risk | Post-Exploit |
| CVE-2022-43551 | LOW3.1 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 16.5% High Exploitation Risk | Post-Exploit |
| CVE-2023-36479 | LOW3.1 | org.eclipse.jetty:jetty-servlets 9.4.48.v20220622 fixed in 9.4.52, 10.0.16, 11.0.16 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-10966 | LOW3.01 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-10966 | LOW3.01 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69420 | LOW3.01 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-22796 | LOW3.01 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9076 | LOW3.01 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-40909 | LOW3.01 | perl-base 5.32.1-4+deb11u2 fixed in 5.32.1-4+deb11u5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-3783 | LOW2.91 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-3783 | LOW2.91 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2024-2511 | LOW2.89 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u2 | 54.0% Actively Exploited | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-4641 | LOW2.8 | login 1:4.8.1-1 fixed in 1:4.8.1-1+deb11u1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | mount 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-22795 | LOW2.8 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-7383 | LOW2.8 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u8 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-4641 | LOW2.8 | passwd 1:4.8.1-1 fixed in 1:4.8.1-1+deb11u1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-5704 | LOW2.8 | tar 1.34+dfsg-1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2022-0563 | LOW2.8 | util-linux 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-4016 | LOW2.8 | libprocps8 2:3.3.17-5 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2021-36084 | LOW2.8 | libsepol1 3.1-1 fixed in 3.1-1+deb11u1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2021-36085 | LOW2.8 | libsepol1 3.1-1 fixed in 3.1-1+deb11u1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2021-36086 | LOW2.8 | libsepol1 3.1-1 fixed in 3.1-1+deb11u1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2021-36087 | LOW2.8 | libsepol1 3.1-1 fixed in 3.1-1+deb11u1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2013-4392 | LOW2.8 | libsystemd0 247.3-7+deb11u1 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libsystemd0 247.3-7+deb11u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2013-4392 | LOW2.8 | libudev1 247.3-7+deb11u1 No fix yet | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 247.3-7+deb11u1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-13595 | LOW2.7 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4873 | LOW2.7 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6253 | LOW2.7 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-7168 | LOW2.7 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-4873 | LOW2.7 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6253 | LOW2.7 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-7168 | LOW2.7 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-13595 | LOW2.7 | mount 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | mount 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42766 | LOW2.7 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u8 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-12087 | LOW2.7 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-13595 | LOW2.7 | util-linux 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-3184 | LOW2.7 | util-linux 2.36.1-8+deb11u1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-28085 | LOW2.64 | bsdutils 1:2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2024-28085 | LOW2.64 | mount 2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2024-28085 | LOW2.64 | util-linux 2.36.1-8+deb11u1 fixed in 2.36.1-8+deb11u2 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34180 | LOW2.55 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u8 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-48959 | LOW2.55 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-48961 | LOW2.55 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2007-5686 | LOW2.5 | login 1:4.8.1-1 No fix yet | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2007-5686 | LOW2.5 | passwd 1:4.8.1-1 No fix yet | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2025-14017 | LOW2.45 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-14017 | LOW2.45 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2017-18018 | LOW2.4 | coreutils 8.32-4+b1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-15224 | LOW2.4 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-30258 | LOW2.4 | gpgv 2.2.27-2+deb11u2 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-68972 | LOW2.4 | gpgv 2.2.27-2+deb11u2 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-41991 | LOW2.4 | gzip 1.10-4+deb11u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-15224 | LOW2.4 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2013-4235 | LOW2.4 | login 1:4.8.1-1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | mount 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-13176 | LOW2.4 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u3 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-68160 | LOW2.4 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2013-4235 | LOW2.4 | passwd 1:4.8.1-1 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.36.1-8+deb11u1 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-0725 | LOW2.4 | curl 7.74.0-1.3+deb11u5 No fix yet | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-0725 | LOW2.4 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-5278 | LOW2.24 | coreutils 8.32-4+b1 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2011-3374 | LOW2.22 | apt 2.2.4 No fix yet | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-28322 | LOW2.22 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u9 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-38546 | LOW2.22 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u10 | 6.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-28322 | LOW2.22 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u9 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-38546 | LOW2.22 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u10 | 6.2% Low-Moderate Risk | Post-Exploit |
| CVE-2024-9143 | LOW2.22 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u2 | 6.0% Low-Moderate Risk | Post-Exploit |
| CVE-2025-69418 | LOW2.04 | openssl 1.1.1n-0+deb11u4 fixed in 1.1.1w-0+deb11u5 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | login 1:4.8.1-1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.8.1-1 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-45310 | LOW1.84 | github.com/opencontainers/runc v1.1.0 fixed in 1.1.14, 1.2.0-rc.3 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2022-3219 | LOW1.68 | gpgv 2.2.27-2+deb11u2 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2023-29383 | LOW1.68 | login 1:4.8.1-1 fixed in 1:4.8.1-1+deb11u1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-29383 | LOW1.68 | passwd 1:4.8.1-1 fixed in 1:4.8.1-1+deb11u1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2011-4116 | LOW1.68 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2023-4016 | LOW1.68 | procps 2:3.3.17-5 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2023-39804 | LOW1.68 | tar 1.34+dfsg-1 fixed in 1.34+dfsg-1+deb11u1 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-68121 | NONE0 | stdlib v1.18.2 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2025-68121 | NONE0 | stdlib v1.19.6 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2023-24538 | NONE0 | stdlib v1.18.2 fixed in 1.19.8, 1.20.3 | 2.3% Low-Moderate Risk | Not Applicable |
| CVE-2023-24540 | NONE0 | stdlib v1.18.2 fixed in 1.19.9, 1.20.4 | 1.5% Low-Moderate Risk | Not Applicable |
| CVE-2024-24790 | NONE0 | stdlib v1.18.2 fixed in 1.21.11, 1.22.4 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2023-24538 | NONE0 | stdlib v1.19.6 fixed in 1.19.8, 1.20.3 | 2.3% Low-Moderate Risk | Not Applicable |
| CVE-2023-24540 | NONE0 | stdlib v1.19.6 fixed in 1.19.9, 1.20.4 | 1.5% Low-Moderate Risk | Not Applicable |
| CVE-2024-24790 | NONE0 | stdlib v1.19.6 fixed in 1.21.11, 1.22.4 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2023-29491 | NONE0 | libncurses6 6.2+20201114-2 fixed in 6.2+20201114-2+deb11u2 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libncurses6 6.2+20201114-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-29491 | NONE0 | libncursesw6 6.2+20201114-2 fixed in 6.2+20201114-2+deb11u2 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libncursesw6 6.2+20201114-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6020 | NONE0 | libpam-modules 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6020 | NONE0 | libpam-modules-bin 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6020 | NONE0 | libpam-runtime 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6020 | NONE0 | libpam0g 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-29491 | NONE0 | libtinfo6 6.2+20201114-2 fixed in 6.2+20201114-2+deb11u2 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libtinfo6 6.2+20201114-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-29491 | NONE0 | ncurses-base 6.2+20201114-2 fixed in 6.2+20201114-2+deb11u2 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-base 6.2+20201114-2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2022-30580 | NONE0 | stdlib v1.18.2 fixed in 1.17.11, 1.18.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-29403 | NONE0 | stdlib v1.18.2 fixed in 1.19.10, 1.20.5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-39822 | NONE0 | stdlib v1.18.2 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2023-29403 | NONE0 | stdlib v1.19.6 fixed in 1.19.10, 1.20.5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-39822 | NONE0 | stdlib v1.19.6 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2022-27664 | NONE0 | stdlib v1.18.2 fixed in 1.18.6, 1.19.1 | 2.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-28131 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2022-2879 | NONE0 | stdlib v1.18.2 fixed in 1.18.7, 1.19.2 | 1.5% Low-Moderate Risk | Not Applicable |
| CVE-2022-2880 | NONE0 | stdlib v1.18.2 fixed in 1.18.7, 1.19.2 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2022-29804 | NONE0 | stdlib v1.18.2 fixed in 1.17.11, 1.18.3 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2022-30630 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-30631 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-30632 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-30633 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-30634 | NONE0 | stdlib v1.18.2 fixed in 1.17.11, 1.18.3 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-30635 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2022-32189 | NONE0 | stdlib v1.18.2 fixed in 1.17.13, 1.18.5 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2022-41715 | NONE0 | stdlib v1.18.2 fixed in 1.18.7, 1.19.2 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2022-41716 | NONE0 | stdlib v1.18.2 fixed in 1.18.8, 1.19.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2022-41720 | NONE0 | stdlib v1.18.2 fixed in 1.18.9, 1.19.4 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2022-41722 | NONE0 | stdlib v1.18.2 fixed in 1.19.6, 1.20.1 | 1.7% Low-Moderate Risk | Not Applicable |
| CVE-2022-41723 | NONE0 | stdlib v1.18.2 fixed in 1.19.6, 1.20.1 | 4.6% Low-Moderate Risk | Not Applicable |
| CVE-2022-41724 | NONE0 | stdlib v1.18.2 fixed in 1.19.6, 1.20.1 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2022-41725 | NONE0 | stdlib v1.18.2 fixed in 1.19.6, 1.20.1 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2023-24534 | NONE0 | stdlib v1.18.2 fixed in 1.19.8, 1.20.3 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2023-24536 | NONE0 | stdlib v1.18.2 fixed in 1.19.8, 1.20.3 | 1.5% Low-Moderate Risk | Not Applicable |
| CVE-2023-24537 | NONE0 | stdlib v1.18.2 fixed in 1.19.8, 1.20.3 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2023-39325 | NONE0 | stdlib v1.18.2 fixed in 1.20.10, 1.21.3 | 3.8% Low-Moderate Risk | Not Applicable |
| CVE-2023-45283 | NONE0 | stdlib v1.18.2 fixed in 1.20.11, 1.21.4, 1.20.12, 1.21.5 | 2.8% Low-Moderate Risk | Not Applicable |
| CVE-2023-45287 | NONE0 | stdlib v1.18.2 fixed in 1.20.0 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2023-45288 | NONE0 | stdlib v1.18.2 fixed in 1.21.9, 1.22.2 | 92.0% Actively Exploited | Not Applicable |
| CVE-2024-34156 | NONE0 | stdlib v1.18.2 fixed in 1.22.7, 1.23.1 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-61726 | NONE0 | stdlib v1.18.2 fixed in 1.24.12, 1.25.6 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2025-61729 | NONE0 | stdlib v1.18.2 fixed in 1.24.11, 1.25.5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-25679 | NONE0 | stdlib v1.18.2 fixed in 1.25.8, 1.26.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-27145 | NONE0 | stdlib v1.18.2 fixed in 1.25.11, 1.26.4 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-32280 | NONE0 | stdlib v1.18.2 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-32281 | NONE0 | stdlib v1.18.2 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-32283 | NONE0 | stdlib v1.18.2 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-33811 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-33814 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-39820 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-39836 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42499 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-42504 | NONE0 | stdlib v1.18.2 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-58183 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-61728 | NONE0 | stdlib v1.18.2 fixed in 1.24.12, 1.25.6 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-24534 | NONE0 | stdlib v1.19.6 fixed in 1.19.8, 1.20.3 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2023-24536 | NONE0 | stdlib v1.19.6 fixed in 1.19.8, 1.20.3 | 1.5% Low-Moderate Risk | Not Applicable |
| CVE-2023-24537 | NONE0 | stdlib v1.19.6 fixed in 1.19.8, 1.20.3 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2023-39325 | NONE0 | stdlib v1.19.6 fixed in 1.20.10, 1.21.3 | 3.8% Low-Moderate Risk | Not Applicable |
| CVE-2023-45283 | NONE0 | stdlib v1.19.6 fixed in 1.20.11, 1.21.4, 1.20.12, 1.21.5 | 2.8% Low-Moderate Risk | Not Applicable |
| CVE-2023-45287 | NONE0 | stdlib v1.19.6 fixed in 1.20.0 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2023-45288 | NONE0 | stdlib v1.19.6 fixed in 1.21.9, 1.22.2 | 92.0% Actively Exploited | Not Applicable |
| CVE-2024-34156 | NONE0 | stdlib v1.19.6 fixed in 1.22.7, 1.23.1 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-61726 | NONE0 | stdlib v1.19.6 fixed in 1.24.12, 1.25.6 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2025-61729 | NONE0 | stdlib v1.19.6 fixed in 1.24.11, 1.25.5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-25679 | NONE0 | stdlib v1.19.6 fixed in 1.25.8, 1.26.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-27145 | NONE0 | stdlib v1.19.6 fixed in 1.25.11, 1.26.4 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-32280 | NONE0 | stdlib v1.19.6 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-32281 | NONE0 | stdlib v1.19.6 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-32283 | NONE0 | stdlib v1.19.6 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-33811 | NONE0 | stdlib v1.19.6 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-33814 | NONE0 | stdlib v1.19.6 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-39820 | NONE0 | stdlib v1.19.6 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-39836 | NONE0 | stdlib v1.19.6 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42499 | NONE0 | stdlib v1.19.6 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-42504 | NONE0 | stdlib v1.19.6 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-58183 | NONE0 | stdlib v1.19.6 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-61728 | NONE0 | stdlib v1.19.6 fixed in 1.24.12, 1.25.6 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-24539 | NONE0 | stdlib v1.18.2 fixed in 1.19.9, 1.20.4 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2023-29400 | NONE0 | stdlib v1.18.2 fixed in 1.19.9, 1.20.4 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2023-24539 | NONE0 | stdlib v1.19.6 fixed in 1.19.9, 1.20.4 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2023-29400 | NONE0 | stdlib v1.19.6 fixed in 1.19.9, 1.20.4 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2022-29458 | NONE0 | libncurses6 6.2+20201114-2 fixed in 6.2+20201114-2+deb11u1 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2022-29458 | NONE0 | libncursesw6 6.2+20201114-2 fixed in 6.2+20201114-2+deb11u1 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2022-29458 | NONE0 | libtinfo6 6.2+20201114-2 fixed in 6.2+20201114-2+deb11u1 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2022-29458 | NONE0 | ncurses-base 6.2+20201114-2 fixed in 6.2+20201114-2+deb11u1 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2025-47907 | NONE0 | stdlib v1.18.2 fixed in 1.23.12, 1.24.6 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-47907 | NONE0 | stdlib v1.19.6 fixed in 1.23.12, 1.24.6 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-4673 | NONE0 | stdlib v1.18.2 fixed in 1.23.10, 1.24.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-4673 | NONE0 | stdlib v1.19.6 fixed in 1.23.10, 1.24.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libncurses6 6.2+20201114-2 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libncursesw6 6.2+20201114-2 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libtinfo6 6.2+20201114-2 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-base 6.2+20201114-2 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2022-1705 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2022-32148 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2023-29406 | NONE0 | stdlib v1.18.2 fixed in 1.19.11, 1.20.6 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2024-24785 | NONE0 | stdlib v1.18.2 fixed in 1.21.8, 1.22.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2025-47906 | NONE0 | stdlib v1.18.2 fixed in 1.23.12, 1.24.6 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-61727 | NONE0 | stdlib v1.18.2 fixed in 1.24.11, 1.25.5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39825 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-29406 | NONE0 | stdlib v1.19.6 fixed in 1.19.11, 1.20.6 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2024-24785 | NONE0 | stdlib v1.19.6 fixed in 1.21.8, 1.22.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2025-47906 | NONE0 | stdlib v1.19.6 fixed in 1.23.12, 1.24.6 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-61727 | NONE0 | stdlib v1.19.6 fixed in 1.24.11, 1.25.5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39825 | NONE0 | stdlib v1.19.6 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32282 | NONE0 | stdlib v1.18.2 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-32282 | NONE0 | stdlib v1.19.6 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2023-39318 | NONE0 | stdlib v1.18.2 fixed in 1.20.8, 1.21.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2023-39319 | NONE0 | stdlib v1.18.2 fixed in 1.20.8, 1.21.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-32289 | NONE0 | stdlib v1.18.2 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2023-39318 | NONE0 | stdlib v1.19.6 fixed in 1.20.8, 1.21.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2023-39319 | NONE0 | stdlib v1.19.6 fixed in 1.20.8, 1.21.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-32289 | NONE0 | stdlib v1.19.6 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-24783 | NONE0 | stdlib v1.18.2 fixed in 1.21.8, 1.22.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2024-24791 | NONE0 | stdlib v1.18.2 fixed in 1.21.12, 1.22.5 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2024-34155 | NONE0 | stdlib v1.18.2 fixed in 1.22.7, 1.23.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2024-34158 | NONE0 | stdlib v1.18.2 fixed in 1.22.7, 1.23.1 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2024-45336 | NONE0 | stdlib v1.18.2 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2024-24783 | NONE0 | stdlib v1.19.6 fixed in 1.21.8, 1.22.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2024-24791 | NONE0 | stdlib v1.19.6 fixed in 1.21.12, 1.22.5 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2024-34155 | NONE0 | stdlib v1.19.6 fixed in 1.22.7, 1.23.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2024-34158 | NONE0 | stdlib v1.19.6 fixed in 1.22.7, 1.23.1 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2024-45336 | NONE0 | stdlib v1.19.6 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2024-22365 | NONE0 | libpam-modules 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2024-22365 | NONE0 | libpam-modules-bin 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2024-22365 | NONE0 | libpam-runtime 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2024-22365 | NONE0 | libpam0g 1.4.0-9+deb11u1 fixed in 1.4.0-9+deb11u2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2022-1962 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2024-24789 | NONE0 | stdlib v1.18.2 fixed in 1.21.11, 1.22.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32288 | NONE0 | stdlib v1.18.2 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-24789 | NONE0 | stdlib v1.19.6 fixed in 1.21.11, 1.22.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32288 | NONE0 | stdlib v1.19.6 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-24784 | NONE0 | stdlib v1.18.2 fixed in 1.21.8, 1.22.1 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-22871 | NONE0 | stdlib v1.18.2 fixed in 1.23.8, 1.24.2 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-27142 | NONE0 | stdlib v1.18.2 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39823 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39826 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-24784 | NONE0 | stdlib v1.19.6 fixed in 1.21.8, 1.22.1 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-22871 | NONE0 | stdlib v1.19.6 fixed in 1.23.8, 1.24.2 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-27142 | NONE0 | stdlib v1.19.6 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39823 | NONE0 | stdlib v1.19.6 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39826 | NONE0 | stdlib v1.19.6 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2022-41717 | NONE0 | stdlib v1.18.2 fixed in 1.18.9, 1.19.4 | 5.6% Low-Moderate Risk | Not Applicable |
| CVE-2023-24532 | NONE0 | stdlib v1.18.2 fixed in 1.19.7, 1.20.2 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2023-29409 | NONE0 | stdlib v1.18.2 fixed in 1.19.12, 1.20.7, 1.21.0-rc.4 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2023-39326 | NONE0 | stdlib v1.18.2 fixed in 1.20.12, 1.21.5 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2023-45284 | NONE0 | stdlib v1.18.2 fixed in 1.20.11, 1.21.4 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2023-45289 | NONE0 | stdlib v1.18.2 fixed in 1.21.8, 1.22.1 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2023-45290 | NONE0 | stdlib v1.18.2 fixed in 1.21.8, 1.22.1 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-22866 | NONE0 | stdlib v1.18.2 fixed in 1.22.12, 1.23.6, 1.24.0-rc.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-22873 | NONE0 | stdlib v1.18.2 fixed in 1.23.9, 1.24.3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-47912 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58185 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-58187 | NONE0 | stdlib v1.18.2 fixed in 1.24.9, 1.25.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58188 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58189 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-61723 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-61724 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-61725 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-61730 | NONE0 | stdlib v1.18.2 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42505 | NONE0 | stdlib v1.18.2 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-42507 | NONE0 | stdlib v1.18.2 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58186 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-24532 | NONE0 | stdlib v1.19.6 fixed in 1.19.7, 1.20.2 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2023-29409 | NONE0 | stdlib v1.19.6 fixed in 1.19.12, 1.20.7, 1.21.0-rc.4 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2023-39326 | NONE0 | stdlib v1.19.6 fixed in 1.20.12, 1.21.5 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2023-45284 | NONE0 | stdlib v1.19.6 fixed in 1.20.11, 1.21.4 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2023-45289 | NONE0 | stdlib v1.19.6 fixed in 1.21.8, 1.22.1 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2023-45290 | NONE0 | stdlib v1.19.6 fixed in 1.21.8, 1.22.1 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-22866 | NONE0 | stdlib v1.19.6 fixed in 1.22.12, 1.23.6, 1.24.0-rc.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-22873 | NONE0 | stdlib v1.19.6 fixed in 1.23.9, 1.24.3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-47912 | NONE0 | stdlib v1.19.6 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58185 | NONE0 | stdlib v1.19.6 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-58187 | NONE0 | stdlib v1.19.6 fixed in 1.24.9, 1.25.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58188 | NONE0 | stdlib v1.19.6 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58189 | NONE0 | stdlib v1.19.6 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-61723 | NONE0 | stdlib v1.19.6 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-61724 | NONE0 | stdlib v1.19.6 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-61725 | NONE0 | stdlib v1.19.6 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-61730 | NONE0 | stdlib v1.19.6 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42505 | NONE0 | stdlib v1.19.6 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-42507 | NONE0 | stdlib v1.19.6 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58186 | NONE0 | stdlib v1.19.6 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-4039 | NONE0 | gcc-10-base 10.2.1-6 No fix yet | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules-bin 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-runtime 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam0g 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-10041 | NONE0 | libpam-modules 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-10041 | NONE0 | libpam-modules-bin 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-10041 | NONE0 | libpam-runtime 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-10041 | NONE0 | libpam0g 1.4.0-9+deb11u1 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-22870 | NONE0 | stdlib v1.18.2 fixed in 1.23.7, 1.24.1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-22870 | NONE0 | stdlib v1.19.6 fixed in 1.23.7, 1.24.1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-45341 | NONE0 | stdlib v1.18.2 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2024-45341 | NONE0 | stdlib v1.19.6 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | libncurses6 6.2+20201114-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | libncursesw6 6.2+20201114-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | libtinfo6 6.2+20201114-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | ncurses-base 6.2+20201114-2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2022-30629 | NONE0 | stdlib v1.18.2 fixed in 1.17.11, 1.18.3 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-27139 | NONE0 | stdlib v1.18.2 fixed in 1.25.8, 1.26.1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-27139 | NONE0 | stdlib v1.19.6 fixed in 1.25.8, 1.26.1 | 0.2% Theoretical Threat | Not Applicable |
| TEMP-0841856-B18BAF | NONE0 | bash 5.1-2+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | bsdutils 1:2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| DLA-4485-1 | NONE0 | ca-certificates 20210119 fixed in 20230311+deb12u1~deb11u1 | — | Not Applicable |
| CVE-2026-8458 | NONE0 | curl 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Not Applicable |
| DLA-4213-1 | NONE0 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u15 | — | Not Applicable |
| DLA-4432-1 | NONE0 | curl 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u16 | — | Not Applicable |
| CVE-2025-6297 | NONE0 | dpkg 1.20.12 fixed in 1.20.14 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-53615 | NONE0 | libblkid1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | libblkid1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-8458 | NONE0 | libcurl4 7.74.0-1.3+deb11u5 No fix yet | 0.5% Theoretical Threat | Not Applicable |
| DLA-4213-1 | NONE0 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u15 | — | Not Applicable |
| DLA-4432-1 | NONE0 | libcurl4 7.74.0-1.3+deb11u5 fixed in 7.74.0-1.3+deb11u16 | — | Not Applicable |
| CVE-2026-53615 | NONE0 | libmount1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | libmount1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | libsmartcols1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2025-27587 | NONE0 | libssl1.1 1.1.1n-0+deb11u4 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-53615 | NONE0 | libuuid1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | libuuid1 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| TEMP-0628843-DBAD28 | NONE0 | login 1:4.8.1-1 No fix yet | — | Not Applicable |
| CVE-2026-53615 | NONE0 | mount 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | mount 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2025-27587 | NONE0 | openssl 1.1.1n-0+deb11u4 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| TEMP-0628843-DBAD28 | NONE0 | passwd 1:4.8.1-1 No fix yet | — | Not Applicable |
| CVE-2026-57433 | NONE0 | perl-base 5.32.1-4+deb11u2 No fix yet | — | Not Applicable |
| CVE-2026-7010 | NONE0 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-7017 | NONE0 | perl-base 5.32.1-4+deb11u2 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| TEMP-0517018-A83CE6 | NONE0 | sysv-rc 2.96-7+deb11u1 No fix yet | — | Not Applicable |
| TEMP-0517018-A83CE6 | NONE0 | sysvinit-utils 2.96-7+deb11u1 No fix yet | — | Not Applicable |
| TEMP-0290435-0B57B5 | NONE0 | tar 1.34+dfsg-1 No fix yet | — | Not Applicable |
| DLA-3972-1 | NONE0 | tzdata 2021a-1+deb11u8 fixed in 2024b-0+deb11u1 | — | Not Applicable |
| DLA-4085-1 | NONE0 | tzdata 2021a-1+deb11u8 fixed in 2025a-0+deb11u1 | — | Not Applicable |
| DLA-4105-1 | NONE0 | tzdata 2021a-1+deb11u8 fixed in 2025b-0+deb11u1 | — | Not Applicable |
| DLA-4403-1 | NONE0 | tzdata 2021a-1+deb11u8 fixed in 2025b-0+deb11u2 | — | Not Applicable |
| DLA-4569-1 | NONE0 | tzdata 2021a-1+deb11u8 fixed in 2026b-0+deb11u1 | — | Not Applicable |
| CVE-2026-53615 | NONE0 | util-linux 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| CVE-2026-53613 | NONE0 | util-linux 2.36.1-8+deb11u1 No fix yet | — | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.13.4 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.13.4 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| CVE-2026-33558 | NONE0 | org.apache.kafka:kafka-clients 3.3.2 fixed in 3.9.2, 4.0.1 | 0.5% Theoretical Threat | Not Applicable |
| GHSA-jgvc-jfgh-rjvv | NONE0 | org.bitbucket.b_c:jose4j 0.7.9 fixed in 0.9.3 | — | Not Applicable |
| CVE-2026-56740 | NONE0 | org.jline:jline-remote-telnet 3.21.0 fixed in 4.2.1 | — | Not Applicable |
| CVE-2026-56741 | NONE0 | org.jline:jline-remote-telnet 3.21.0 fixed in 4.2.1 | — | Not Applicable |
| CVE-2026-41579 | NONE0 | github.com/opencontainers/runc v1.1.0 fixed in 1.3.6, 1.4.3, 1.5.0-rc.3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.0.0-20220907062415-87db552b00fd fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-0913 | NONE0 | stdlib v1.18.2 fixed in 1.23.10, 1.24.4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.2.0 fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-0913 | NONE0 | stdlib v1.19.6 fixed in 1.23.10, 1.24.4 | 0.2% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.