Last scanned:
AI verdict failed due to an error.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-15467 | MEDIUM6.76 | openssl 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2024-6119 | MEDIUM5.85 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 66.6% Actively Exploited | Post-Exploit |
| CVE-2026-31789 | MEDIUM5 | openssl 3.0.18-1.ph5 fixed in 3.0.18-3.ph5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-45447 | MEDIUM4.86 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45445 | MEDIUM4.64 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-28388 | MEDIUM4.5 | openssl 3.0.18-1.ph5 fixed in 3.0.18-3.ph5 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | MEDIUM4.5 | openssl 3.0.18-1.ph5 fixed in 3.0.18-3.ph5 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | MEDIUM4.5 | openssl 3.0.18-1.ph5 fixed in 3.0.18-3.ph5 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34183 | MEDIUM4.5 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2025-15079 | MEDIUM4.13 | curl 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-28387 | MEDIUM4.13 | openssl 3.0.18-1.ph5 fixed in 3.0.18-3.ph5 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2023-6129 | LOW3.9 | openssl 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-5773 | LOW3.82 | curl 8.16.0-1.ph5 fixed in 8.19.0-2.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-6276 | LOW3.82 | curl 8.16.0-1.ph5 fixed in 8.19.0-2.ph5 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-69421 | LOW3.82 | openssl 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-34182 | LOW3.77 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-0306 | LOW3.77 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-69419 | LOW3.77 | openssl 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-31790 | LOW3.54 | openssl 3.0.18-1.ph5 fixed in 3.0.18-3.ph5 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42764 | LOW3.54 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-6237 | LOW3.54 | openssl 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9231 | LOW3.54 | openssl 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-13034 | LOW3.47 | curl 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-14819 | LOW3.47 | curl 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-1965 | LOW3.47 | curl 8.16.0-1.ph5 fixed in 8.19.0-1.ph5 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-9230 | LOW3.36 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2025-14524 | LOW3.31 | curl 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-3784 | LOW3.31 | curl 8.16.0-1.ph5 fixed in 8.19.0-1.ph5 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | curl 8.16.0-1.ph5 fixed in 8.19.0-2.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6429 | LOW3.31 | curl 8.16.0-1.ph5 fixed in 8.19.0-2.ph5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2024-0727 | LOW3.3 | openssl 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 3.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-3805 | LOW3.21 | curl 8.16.0-1.ph5 fixed in 8.19.0-1.ph5 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-34181 | LOW3.21 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-42768 | LOW3.21 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2023-5678 | LOW3.18 | openssl 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2025-10966 | LOW3.01 | curl 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69420 | LOW3.01 | openssl 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-42765 | LOW3.01 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9076 | LOW3.01 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-15468 | LOW3.01 | openssl 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2025-66199 | LOW3.01 | openssl 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-22796 | LOW3.01 | openssl 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42769 | LOW3.01 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42770 | LOW3.01 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-34180 | LOW3 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-3783 | LOW2.91 | curl 8.16.0-1.ph5 fixed in 8.19.0-1.ph5 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2024-2511 | LOW2.89 | openssl 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 54.0% Actively Exploited | Post-Exploit |
| CVE-2026-7383 | LOW2.8 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-15469 | LOW2.8 | openssl 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-22795 | LOW2.8 | openssl 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-4873 | LOW2.7 | curl 8.16.0-1.ph5 fixed in 8.19.0-2.ph5 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6253 | LOW2.7 | curl 8.16.0-1.ph5 fixed in 8.19.0-2.ph5 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-7009 | LOW2.7 | curl 8.16.0-1.ph5 fixed in 8.20.0-1.ph5 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-7168 | LOW2.7 | curl 8.16.0-1.ph5 fixed in 8.20.0-1.ph5 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42766 | LOW2.7 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-42767 | LOW2.7 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-14017 | LOW2.45 | curl 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-15224 | LOW2.4 | curl 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-13176 | LOW2.4 | openssl 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-68160 | LOW2.4 | openssl 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2024-9143 | LOW2.22 | openssl 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 5.8% Low-Moderate Risk | Post-Exploit |
| CVE-2025-69418 | LOW2.04 | openssl 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-45446 | LOW1.89 | openssl 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-68121 | NONE0 | stdlib v1.24.10 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-2781 | NONE0 | nss-libs 3.78-11.ph5 fixed in 3.78-12.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-15467 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 47.6% High Exploitation Risk | Not Applicable |
| CVE-2026-31789 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-3.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-41889 | NONE0 | github.com/jackc/pgx/v4 v4.18.3 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-7598 | NONE0 | libssh2 1.11.0-4.ph5 fixed in 1.11.1-3.ph5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-45445 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-33186 | NONE0 | google.golang.org/grpc v1.72.1 fixed in 1.79.3 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2026-39828 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-39832 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-55200 | NONE0 | libssh2 1.11.0-4.ph5 fixed in 1.11.1-4.ph5 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-39821 | NONE0 | golang.org/x/net v0.42.0 fixed in 0.55.0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-15079 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-0861 | NONE0 | glibc 2.36-20.ph5 fixed in 2.36-22.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-0861 | NONE0 | glibc-libs 2.36-20.ph5 fixed in 2.36-22.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-28387 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-3.ph5 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-45447 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 5.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-39831 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-25681 | NONE0 | golang.org/x/net v0.42.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-27136 | NONE0 | golang.org/x/net v0.42.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-15558 | NONE0 | github.com/docker/cli v27.1.1+incompatible fixed in 29.2.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-6020 | NONE0 | Linux-PAM 1.5.3-10.ph5 fixed in 1.5.3-11.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-25210 | NONE0 | expat-libs 2.7.3-1.ph5 fixed in 2.7.4-1.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-libs 6.5-1.ph5 fixed in 6.5-2.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-39822 | NONE0 | stdlib v1.24.10 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-5773 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.19.0-2.ph5 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-6276 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.19.0-2.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-45186 | NONE0 | expat-libs 2.7.3-1.ph5 fixed in 2.8.1-1.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-55199 | NONE0 | libssh2 1.11.0-4.ph5 fixed in 1.11.1-5.ph5 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2024-6119 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 66.6% Actively Exploited | Not Applicable |
| CVE-2025-69421 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-28388 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-3.ph5 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2026-28389 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-3.ph5 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-28390 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-3.ph5 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-34183 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-32952 | NONE0 | github.com/Azure/go-ntlmssp v0.0.0-20221128193559-754e69321358 fixed in 0.1.1 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2026-35172 | NONE0 | github.com/distribution/distribution v2.8.2+incompatible No fix yet | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-34986 | NONE0 | github.com/go-jose/go-jose/v4 v4.0.5 fixed in 4.1.4 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-32286 | NONE0 | github.com/jackc/pgproto3/v2 v2.3.3 No fix yet | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-39882 | NONE0 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.34.0 fixed in 1.43.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-47913 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.43.0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-39829 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-39830 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-39835 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-46597 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-33814 | NONE0 | golang.org/x/net v0.42.0 fixed in 0.53.0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2025-61726 | NONE0 | stdlib v1.24.10 fixed in 1.24.12, 1.25.6 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2025-61729 | NONE0 | stdlib v1.24.10 fixed in 1.24.11, 1.25.5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-25679 | NONE0 | stdlib v1.24.10 fixed in 1.25.8, 1.26.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-27145 | NONE0 | stdlib v1.24.10 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-32280 | NONE0 | stdlib v1.24.10 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-32281 | NONE0 | stdlib v1.24.10 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32283 | NONE0 | stdlib v1.24.10 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-33811 | NONE0 | stdlib v1.24.10 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-33814 | NONE0 | stdlib v1.24.10 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-39820 | NONE0 | stdlib v1.24.10 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-39836 | NONE0 | stdlib v1.24.10 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42499 | NONE0 | stdlib v1.24.10 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-42504 | NONE0 | stdlib v1.24.10 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-61728 | NONE0 | stdlib v1.24.10 fixed in 1.24.12, 1.25.6 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-34182 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-0306 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-69419 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-42508 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-46595 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-39883 | NONE0 | go.opentelemetry.io/otel/sdk v1.35.0 fixed in 1.43.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-13034 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-14819 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-1965 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.19.0-1.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-14524 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-3784 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.19.0-1.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-5545 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.19.0-2.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-6429 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.19.0-2.ph5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-4437 | NONE0 | glibc 2.36-20.ph5 fixed in 2.36-23.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-4437 | NONE0 | glibc-libs 2.36-20.ph5 fixed in 2.36-23.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-9149 | NONE0 | libsolv 0.7.22-7.ph5 fixed in 0.7.22-7.2.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-9150 | NONE0 | libsolv 0.7.22-7.ph5 fixed in 0.7.22-7.2.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-6129 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 2.3% Low-Moderate Risk | Not Applicable |
| CVE-2026-41888 | NONE0 | github.com/distribution/distribution v2.8.2+incompatible No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39827 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39834 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-25680 | NONE0 | golang.org/x/net v0.42.0 fixed in 0.55.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-61727 | NONE0 | stdlib v1.24.10 fixed in 1.24.11, 1.25.5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39825 | NONE0 | stdlib v1.24.10 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32282 | NONE0 | stdlib v1.24.10 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-3805 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.19.0-1.ph5 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-34181 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-42768 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42502 | NONE0 | golang.org/x/net v0.42.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-32289 | NONE0 | stdlib v1.24.10 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-10966 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-15281 | NONE0 | glibc 2.36-20.ph5 fixed in 2.36-22.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-15281 | NONE0 | glibc-libs 2.36-20.ph5 fixed in 2.36-22.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69420 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-31790 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-3.ph5 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-42764 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-42765 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-9076 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-6237 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 2.3% Low-Moderate Risk | Not Applicable |
| CVE-2025-15468 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-66199 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-9231 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-22796 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-42769 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-42770 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-3783 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.19.0-1.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-9230 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 1.7% Low-Moderate Risk | Not Applicable |
| CVE-2026-32776 | NONE0 | expat-libs 2.7.3-1.ph5 fixed in 2.7.5-1.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-32777 | NONE0 | expat-libs 2.7.3-1.ph5 fixed in 2.7.5-1.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-32778 | NONE0 | expat-libs 2.7.3-1.ph5 fixed in 2.7.5-1.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-7383 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2024-0727 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 3.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-15469 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.0.18-2.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-22795 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-27171 | NONE0 | zlib 1.2.13-4.ph5 fixed in 1.3.2-1.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-39833 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32288 | NONE0 | stdlib v1.24.10 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42506 | NONE0 | golang.org/x/net v0.42.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-27142 | NONE0 | stdlib v1.24.10 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39823 | NONE0 | stdlib v1.24.10 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39826 | NONE0 | stdlib v1.24.10 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-4873 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.19.0-2.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-6253 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.19.0-2.ph5 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-7009 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.20.0-1.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-7168 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.20.0-1.ph5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-0915 | NONE0 | glibc 2.36-20.ph5 fixed in 2.36-22.ph5 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-4046 | NONE0 | glibc 2.36-20.ph5 fixed in 2.36-23.1.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-0915 | NONE0 | glibc-libs 2.36-20.ph5 fixed in 2.36-22.ph5 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-4046 | NONE0 | glibc-libs 2.36-20.ph5 fixed in 2.36-23.1.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-5678 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 4.5% Low-Moderate Risk | Not Applicable |
| CVE-2026-42766 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 1.0% Theoretical Threat | Not Applicable |
| CVE-2026-42767 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-34743 | NONE0 | xz-libs 5.4.0-5.ph5 fixed in 5.4.0-6.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-47914 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-58181 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.45.0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-46598 | NONE0 | golang.org/x/crypto v0.41.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-47911 | NONE0 | golang.org/x/net v0.42.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-58190 | NONE0 | golang.org/x/net v0.42.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-61730 | NONE0 | stdlib v1.24.10 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42505 | NONE0 | stdlib v1.24.10 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42507 | NONE0 | stdlib v1.24.10 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-5450 | NONE0 | glibc 2.36-20.ph5 fixed in 2.36-23.1.2.ph5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-5928 | NONE0 | glibc 2.36-20.ph5 fixed in 2.36-23.1.2.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-5450 | NONE0 | glibc-libs 2.36-20.ph5 fixed in 2.36-23.1.2.ph5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-5928 | NONE0 | glibc-libs 2.36-20.ph5 fixed in 2.36-23.1.2.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-11850 | NONE0 | krb5 1.20.2-10.ph5 fixed in 1.20.2-14.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-34180 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-14017 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-15224 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.18.0-1.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-13176 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-68160 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-35206 | NONE0 | helm.sh/helm/v3 v3.19.0 fixed in 3.20.2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-4438 | NONE0 | glibc 2.36-20.ph5 fixed in 2.36-23.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-4438 | NONE0 | glibc-libs 2.36-20.ph5 fixed in 2.36-23.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-69418 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-41080 | NONE0 | expat-libs 2.7.3-1.ph5 fixed in 2.8.0-1.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-2511 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 54.0% Actively Exploited | Not Applicable |
| CVE-2024-9143 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-2.ph5 | 5.8% Low-Moderate Risk | Not Applicable |
| CVE-2026-45446 | NONE0 | openssl-libs 3.0.18-1.ph5 fixed in 3.5.7-1.ph5 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-70873 | NONE0 | sqlite-libs 3.43.2-5.ph5 fixed in 3.43.2-6.ph5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-33540 | NONE0 | github.com/distribution/distribution v2.8.2+incompatible No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-24515 | NONE0 | expat-libs 2.7.3-1.ph5 fixed in 2.7.4-1.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-27139 | NONE0 | stdlib v1.24.10 fixed in 1.25.8, 1.26.1 | 0.2% Theoretical Threat | Not Applicable |
| BDSA-2026-9096 | NONE0 | curl 8.16.0-1.ph5 fixed in 8.20.0-1.ph5 | — | Not Applicable |
| BDSA-2026-9096 | NONE0 | curl-libs 8.16.0-1.ph5 fixed in 8.20.0-1.ph5 | — | Not Applicable |
| BDSA-2026-9020 | NONE0 | libssh2 1.11.0-4.ph5 fixed in 1.11.1-3.ph5 | — | Not Applicable |
| CVE-2026-11822 | NONE0 | sqlite-libs 3.43.2-5.ph5 fixed in 3.43.2-7.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-11824 | NONE0 | sqlite-libs 3.43.2-5.ph5 fixed in 3.43.2-7.ph5 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-24358 | NONE0 | github.com/gorilla/csrf v1.7.2 fixed in 1.7.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-47909 | NONE0 | github.com/gorilla/csrf v1.7.2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-2303 | NONE0 | go.mongodb.org/mongo-driver v1.14.0 fixed in 1.17.7 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-24051 | NONE0 | go.opentelemetry.io/otel/sdk v1.35.0 fixed in 1.40.0 | 0.2% Theoretical Threat | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.41.0 No fix yet | — | Not Applicable |
| CVE-2026-46600 | NONE0 | golang.org/x/net v0.42.0 fixed in 0.56.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.35.0 fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56852 | NONE0 | golang.org/x/text v0.28.0 fixed in 0.39.0 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.72.1 fixed in 1.82.1 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.