Last scanned:
AI verdict failed due to an error.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-15467 | MEDIUM6.76 | openssl 3.0.13-3.ph4 fixed in 3.0.18-2.ph4 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2024-6119 | MEDIUM5.85 | openssl 3.0.13-3.ph4 fixed in 3.0.15-1.ph4 | 66.6% Actively Exploited | Post-Exploit |
| CVE-2026-31789 | MEDIUM5 | openssl 3.0.13-3.ph4 fixed in 3.0.18-3.ph4 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-45447 | MEDIUM4.86 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45445 | MEDIUM4.64 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2024-6197 | MEDIUM4.5 | curl 8.1.2-8.ph4 fixed in 8.7.1-2.ph4 | 4.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28388 | MEDIUM4.5 | openssl 3.0.13-3.ph4 fixed in 3.0.18-3.ph4 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | MEDIUM4.5 | openssl 3.0.13-3.ph4 fixed in 3.0.18-3.ph4 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | MEDIUM4.5 | openssl 3.0.13-3.ph4 fixed in 3.0.18-3.ph4 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34183 | MEDIUM4.5 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2024-7264 | MEDIUM4.48 | curl 8.1.2-8.ph4 fixed in 8.7.1-3.ph4 | 17.3% High Exploitation Risk | Post-Exploit |
| CVE-2025-15079 | MEDIUM4.13 | curl 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-28387 | MEDIUM4.13 | openssl 3.0.13-3.ph4 fixed in 3.0.18-3.ph4 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2023-46218 | LOW3.9 | curl 8.1.2-8.ph4 fixed in 8.7.1-1.ph4 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-9681 | LOW3.9 | curl 8.1.2-8.ph4 fixed in 8.7.1-4.ph4 | 2.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-5773 | LOW3.82 | curl 8.1.2-8.ph4 fixed in 8.19.0-2.ph4 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-6276 | LOW3.82 | curl 8.1.2-8.ph4 fixed in 8.19.0-2.ph4 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-69421 | LOW3.82 | openssl 3.0.13-3.ph4 fixed in 3.0.18-2.ph4 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-34182 | LOW3.77 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69419 | LOW3.77 | openssl 3.0.13-3.ph4 fixed in 3.0.18-2.ph4 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-11053 | LOW3.54 | curl 8.1.2-8.ph4 fixed in 8.12.0-1.ph4 | 1.4% Low-Moderate Risk | Post-Exploit |
| CVE-2024-5535 | LOW3.54 | openssl 3.0.13-3.ph4 fixed in 3.0.14-2.ph4 | 5.6% Low-Moderate Risk | Post-Exploit |
| CVE-2026-31790 | LOW3.54 | openssl 3.0.13-3.ph4 fixed in 3.0.18-3.ph4 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42764 | LOW3.54 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-13034 | LOW3.47 | curl 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-14819 | LOW3.47 | curl 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-1965 | LOW3.47 | curl 8.1.2-8.ph4 fixed in 8.19.0-1.ph4 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2024-4741 | LOW3.36 | openssl 3.0.13-3.ph4 fixed in 3.0.14-1.ph4 | 2.9% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9230 | LOW3.36 | openssl 3.0.13-3.ph4 fixed in 3.0.18-1.ph4 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2024-8096 | LOW3.31 | curl 8.1.2-8.ph4 fixed in 8.12.0-1.ph4 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2025-14524 | LOW3.31 | curl 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-4947 | LOW3.31 | curl 8.1.2-8.ph4 fixed in 8.16.0-1.ph4 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-3784 | LOW3.31 | curl 8.1.2-8.ph4 fixed in 8.19.0-1.ph4 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | curl 8.1.2-8.ph4 fixed in 8.19.0-2.ph4 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6429 | LOW3.31 | curl 8.1.2-8.ph4 fixed in 8.19.0-2.ph4 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-34181 | LOW3.21 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-9086 | LOW3.18 | curl 8.1.2-8.ph4 fixed in 8.16.0-1.ph4 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2023-46219 | LOW3.18 | curl 8.1.2-8.ph4 fixed in 8.7.1-1.ph4 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-10966 | LOW3.01 | curl 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69420 | LOW3.01 | openssl 3.0.13-3.ph4 fixed in 3.0.18-2.ph4 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-42765 | LOW3.01 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9076 | LOW3.01 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-22796 | LOW3.01 | openssl 3.0.13-3.ph4 fixed in 3.0.18-2.ph4 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42770 | LOW3.01 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-34180 | LOW3 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-3783 | LOW2.91 | curl 8.1.2-8.ph4 fixed in 8.19.0-1.ph4 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2024-2511 | LOW2.89 | openssl 3.0.13-3.ph4 fixed in 3.0.13-4.ph4 | 54.0% Actively Exploited | Post-Exploit |
| CVE-2026-7383 | LOW2.8 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-22795 | LOW2.8 | openssl 3.0.13-3.ph4 fixed in 3.0.18-2.ph4 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-4873 | LOW2.7 | curl 8.1.2-8.ph4 fixed in 8.19.0-2.ph4 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-6253 | LOW2.7 | curl 8.1.2-8.ph4 fixed in 8.19.0-2.ph4 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-7168 | LOW2.7 | curl 8.1.2-8.ph4 fixed in 8.20.0-1.ph4 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42766 | LOW2.7 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2025-10148 | LOW2.45 | curl 8.1.2-8.ph4 fixed in 8.16.0-1.ph4 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-14017 | LOW2.45 | curl 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-5025 | LOW2.45 | curl 8.1.2-8.ph4 fixed in 8.16.0-1.ph4 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-15224 | LOW2.4 | curl 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-68160 | LOW2.4 | openssl 3.0.13-3.ph4 fixed in 3.0.18-2.ph4 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2024-9143 | LOW2.22 | openssl 3.0.13-3.ph4 fixed in 3.0.16-1.ph4 | 5.8% Low-Moderate Risk | Post-Exploit |
| CVE-2025-69418 | LOW2.04 | openssl 3.0.13-3.ph4 fixed in 3.0.18-2.ph4 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-45446 | LOW1.89 | openssl 3.0.13-3.ph4 fixed in 3.0.21-1.ph4 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-9232 | LOW1.86 | openssl 3.0.13-3.ph4 fixed in 3.0.18-2.ph4 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-68121 | NONE0 | stdlib v1.21.9 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2024-45491 | NONE0 | expat-libs 2.4.9-2.ph4 fixed in 2.4.9-3.ph4 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2024-45492 | NONE0 | expat-libs 2.4.9-2.ph4 fixed in 2.4.9-3.ph4 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2024-56171 | NONE0 | libxml2 2.9.12-13.ph4 fixed in 2.9.12-15.ph4 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2026-2781 | NONE0 | nss-libs 3.72-5.ph4 fixed in 3.72-7.ph4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-41889 | NONE0 | github.com/jackc/pgx/v4 v4.18.2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-24790 | NONE0 | stdlib v1.21.9 fixed in 1.21.11, 1.22.4 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-30223 | NONE0 | github.com/beego/beego/v2 v2.0.6 fixed in 2.3.6 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2024-37371 | NONE0 | krb5 1.17-10.ph4 fixed in 1.17-12.ph4 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2025-49794 | NONE0 | libxml2 2.9.12-13.ph4 fixed in 2.9.12-18.ph4 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-49796 | NONE0 | libxml2 2.9.12-13.ph4 fixed in 2.9.12-18.ph4 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2026-33186 | NONE0 | google.golang.org/grpc v1.58.3 fixed in 1.79.3 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2024-3596 | NONE0 | krb5 1.17-10.ph4 fixed in 1.17-14.ph4 | 14.9% High Exploitation Risk | Not Applicable |
| CVE-2024-2961 | NONE0 | glibc 2.32-16.ph4 fixed in 2.32-17.ph4 | 88.3% Actively Exploited | Not Applicable |
| CVE-2024-40464 | NONE0 | github.com/beego/beego/v2 v2.0.6 fixed in 2.2.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2024-40465 | NONE0 | github.com/beego/beego/v2 v2.0.6 fixed in 2.2.1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-39828 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-39832 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-53547 | NONE0 | helm.sh/helm/v3 v3.14.2 fixed in 3.18.4, 3.17.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-45337 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.31.0 | 3.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-39821 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.55.0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-15079 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-0861 | NONE0 | glibc 2.32-16.ph4 fixed in 2.32-22.ph4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-39831 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-25681 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-27136 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-1372 | NONE0 | elfutils-libelf 0.181-7.ph4 fixed in 0.181-8.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2022-49043 | NONE0 | libxml2 2.9.12-13.ph4 fixed in 2.9.12-18.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-libs 6.2-6.ph4 fixed in 6.5-2.ph4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-39822 | NONE0 | stdlib v1.21.9 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-24928 | NONE0 | libxml2 2.9.12-13.ph4 fixed in 2.9.12-15.ph4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6965 | NONE0 | sqlite-libs 3.38.5-4.ph4 fixed in 3.38.5-6.ph4 | 74.4% Actively Exploited | Not Applicable |
| CVE-2024-33599 | NONE0 | glibc 2.32-16.ph4 fixed in 2.32-18.ph4 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2024-6197 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.7.1-2.ph4 | 4.3% Low-Moderate Risk | Not Applicable |
| CVE-2026-5773 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.19.0-2.ph4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-6276 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.19.0-2.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-1352 | NONE0 | elfutils-libelf 0.181-7.ph4 fixed in 0.181-8.ph4 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2024-45490 | NONE0 | expat-libs 2.4.9-2.ph4 fixed in 2.4.9-3.ph4 | 1.7% Low-Moderate Risk | Not Applicable |
| CVE-2024-8176 | NONE0 | expat-libs 2.4.9-2.ph4 fixed in 2.7.1-1.ph4 | 1.6% Low-Moderate Risk | Not Applicable |
| CVE-2026-45186 | NONE0 | expat-libs 2.4.9-2.ph4 fixed in 2.8.1-1.ph4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-37370 | NONE0 | krb5 1.17-10.ph4 fixed in 1.17-12.ph4 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2025-27113 | NONE0 | libxml2 2.9.12-13.ph4 fixed in 2.9.12-15.ph4 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-32414 | NONE0 | libxml2 2.9.12-13.ph4 fixed in 2.9.12-17.ph4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-32415 | NONE0 | libxml2 2.9.12-13.ph4 fixed in 2.9.12-16.ph4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-6021 | NONE0 | libxml2 2.9.12-13.ph4 fixed in 2.9.12-18.ph4 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2024-0743 | NONE0 | nss-libs 3.72-5.ph4 fixed in 3.72-6.ph4 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2026-32952 | NONE0 | github.com/Azure/go-ntlmssp v0.0.0-20200615164410-66371956d46c fixed in 0.1.1 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2024-55885 | NONE0 | github.com/beego/beego/v2 v2.0.6 fixed in 2.3.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-35172 | NONE0 | github.com/distribution/distribution v2.8.2+incompatible No fix yet | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-30204 | NONE0 | github.com/golang-jwt/jwt/v4 v4.2.0 fixed in 4.5.2 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-32286 | NONE0 | github.com/jackc/pgproto3/v2 v2.3.3 No fix yet | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-39882 | NONE0 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.3.0 fixed in 1.43.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-22869 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.35.0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2025-47913 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.43.0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-39829 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-39830 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-39835 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-46597 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2023-45288 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.23.0 | 92.0% Actively Exploited | Not Applicable |
| CVE-2024-45338 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.33.0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-33814 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.53.0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2025-22868 | NONE0 | golang.org/x/oauth2 v0.10.0 fixed in 0.27.0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2024-34156 | NONE0 | stdlib v1.21.9 fixed in 1.22.7, 1.23.1 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-61726 | NONE0 | stdlib v1.21.9 fixed in 1.24.12, 1.25.6 | 1.9% Low-Moderate Risk | Not Applicable |
| CVE-2025-61729 | NONE0 | stdlib v1.21.9 fixed in 1.24.11, 1.25.5 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-25679 | NONE0 | stdlib v1.21.9 fixed in 1.25.8, 1.26.1 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-27145 | NONE0 | stdlib v1.21.9 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-32280 | NONE0 | stdlib v1.21.9 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-32281 | NONE0 | stdlib v1.21.9 fixed in 1.25.9, 1.26.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32283 | NONE0 | stdlib v1.21.9 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-33811 | NONE0 | stdlib v1.21.9 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-33814 | NONE0 | stdlib v1.21.9 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-39820 | NONE0 | stdlib v1.21.9 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-39836 | NONE0 | stdlib v1.21.9 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42499 | NONE0 | stdlib v1.21.9 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-42504 | NONE0 | stdlib v1.21.9 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-58183 | NONE0 | stdlib v1.21.9 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-61728 | NONE0 | stdlib v1.21.9 fixed in 1.24.12, 1.25.6 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-42508 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-46595 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-4802 | NONE0 | glibc 2.32-16.ph4 fixed in 2.32-21.ph4 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-47907 | NONE0 | stdlib v1.21.9 fixed in 1.23.12, 1.24.6 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-13034 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-14819 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-1965 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.19.0-1.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-4673 | NONE0 | stdlib v1.21.9 fixed in 1.23.10, 1.24.4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-46218 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.7.1-1.ph4 | 1.7% Low-Moderate Risk | Not Applicable |
| CVE-2024-7264 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.7.1-3.ph4 | 17.3% High Exploitation Risk | Not Applicable |
| CVE-2024-8096 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.12.0-1.ph4 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2024-9681 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.7.1-4.ph4 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-14524 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-4947 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.16.0-1.ph4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-3784 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.19.0-1.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-5545 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.19.0-2.ph4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-6429 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.19.0-2.ph4 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-24528 | NONE0 | krb5 1.17-10.ph4 fixed in 1.17-15.ph4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2024-28110 | NONE0 | github.com/cloudevents/sdk-go/v2 v2.13.0 fixed in 2.15.2 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-41888 | NONE0 | github.com/distribution/distribution v2.8.2+incompatible No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39827 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39834 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-22872 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.38.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-25680 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.55.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-32386 | NONE0 | helm.sh/helm/v3 v3.14.2 fixed in 3.17.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-32387 | NONE0 | helm.sh/helm/v3 v3.14.2 fixed in 3.17.3 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-55198 | NONE0 | helm.sh/helm/v3 v3.14.2 fixed in 3.18.5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-55199 | NONE0 | helm.sh/helm/v3 v3.14.2 fixed in 3.18.5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-47906 | NONE0 | stdlib v1.21.9 fixed in 1.23.12, 1.24.6 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-61727 | NONE0 | stdlib v1.21.9 fixed in 1.24.11, 1.25.5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39825 | NONE0 | stdlib v1.21.9 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32282 | NONE0 | stdlib v1.21.9 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42502 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-32289 | NONE0 | stdlib v1.21.9 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-10966 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-11053 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.12.0-1.ph4 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2024-50602 | NONE0 | expat-libs 2.4.9-2.ph4 fixed in 2.4.9-4.ph4 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-15281 | NONE0 | glibc 2.32-16.ph4 fixed in 2.32-22.ph4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-26461 | NONE0 | krb5 1.17-10.ph4 fixed in 1.17-11.ph4 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2024-26458 | NONE0 | krb5 1.17-10.ph4 fixed in 1.17-11.ph4 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2023-48795 | NONE0 | libssh2 1.11.0-1.ph4 fixed in 1.11.0-2.ph4 | 93.3% Actively Exploited | Not Applicable |
| CVE-2024-24786 | NONE0 | google.golang.org/protobuf v1.31.0 fixed in 1.33.0 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2024-24791 | NONE0 | stdlib v1.21.9 fixed in 1.21.12, 1.22.5 | 1.4% Low-Moderate Risk | Not Applicable |
| CVE-2024-34155 | NONE0 | stdlib v1.21.9 fixed in 1.22.7, 1.23.1 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2024-34158 | NONE0 | stdlib v1.21.9 fixed in 1.22.7, 1.23.1 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2024-45336 | NONE0 | stdlib v1.21.9 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-3783 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.19.0-1.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-1377 | NONE0 | elfutils-libelf 0.181-7.ph4 fixed in 0.181-8.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-32776 | NONE0 | expat-libs 2.4.9-2.ph4 fixed in 2.7.5-1.ph4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-32777 | NONE0 | expat-libs 2.4.9-2.ph4 fixed in 2.7.5-1.ph4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-32778 | NONE0 | expat-libs 2.4.9-2.ph4 fixed in 2.7.5-1.ph4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-0395 | NONE0 | glibc 2.32-16.ph4 fixed in 2.32-22.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-34459 | NONE0 | libxml2 2.9.12-13.ph4 fixed in 2.9.12-14.ph4 | 2.3% Low-Moderate Risk | Not Applicable |
| CVE-2025-29088 | NONE0 | sqlite-libs 3.38.5-4.ph4 fixed in 3.38.5-5.ph4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-39833 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-24789 | NONE0 | stdlib v1.21.9 fixed in 1.21.11, 1.22.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-32288 | NONE0 | stdlib v1.21.9 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42506 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-22871 | NONE0 | stdlib v1.21.9 fixed in 1.23.8, 1.24.2 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-27142 | NONE0 | stdlib v1.21.9 fixed in 1.25.8, 1.26.1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39823 | NONE0 | stdlib v1.21.9 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39826 | NONE0 | stdlib v1.21.9 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-9086 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.16.0-1.ph4 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2023-46219 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.7.1-1.ph4 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2026-4873 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.19.0-2.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-6253 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.19.0-2.ph4 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-7168 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.20.0-1.ph4 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-59375 | NONE0 | expat-libs 2.4.9-2.ph4 fixed in 2.7.3-1.ph4 | 1.3% Low-Moderate Risk | Not Applicable |
| CVE-2026-0915 | NONE0 | glibc 2.32-16.ph4 fixed in 2.32-22.ph4 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2024-33600 | NONE0 | glibc 2.32-16.ph4 fixed in 2.32-18.ph4 | 1.2% Low-Moderate Risk | Not Applicable |
| CVE-2025-47914 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-58181 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.45.0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-46598 | NONE0 | golang.org/x/crypto v0.20.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-47911 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-58190 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.45.0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-22866 | NONE0 | stdlib v1.21.9 fixed in 1.22.12, 1.23.6, 1.24.0-rc.3 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-22873 | NONE0 | stdlib v1.21.9 fixed in 1.23.9, 1.24.3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-47912 | NONE0 | stdlib v1.21.9 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58185 | NONE0 | stdlib v1.21.9 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-58187 | NONE0 | stdlib v1.21.9 fixed in 1.24.9, 1.25.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58188 | NONE0 | stdlib v1.21.9 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58189 | NONE0 | stdlib v1.21.9 fixed in 1.24.8, 1.25.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-61723 | NONE0 | stdlib v1.21.9 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-61724 | NONE0 | stdlib v1.21.9 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-61725 | NONE0 | stdlib v1.21.9 fixed in 1.24.8, 1.25.2 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-61730 | NONE0 | stdlib v1.21.9 fixed in 1.24.12, 1.25.6 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42505 | NONE0 | stdlib v1.21.9 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-42507 | NONE0 | stdlib v1.21.9 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-58186 | NONE0 | stdlib v1.21.9 fixed in 1.24.8, 1.25.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-5450 | NONE0 | glibc 2.32-16.ph4 fixed in 2.32-23.ph4 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-10148 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.16.0-1.ph4 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-14017 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-5025 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.16.0-1.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-15224 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.18.0-1.ph4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-1376 | NONE0 | elfutils-libelf 0.181-7.ph4 fixed in 0.181-8.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-22870 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.36.0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-35206 | NONE0 | helm.sh/helm/v3 v3.14.2 fixed in 3.20.2 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-22870 | NONE0 | stdlib v1.21.9 fixed in 1.23.7, 1.24.1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2024-28180 | NONE0 | gopkg.in/square/go-jose.v2 v2.5.1 No fix yet | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-8058 | NONE0 | glibc 2.32-16.ph4 fixed in 2.32-22.ph4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-45341 | NONE0 | stdlib v1.21.9 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2024-33601 | NONE0 | glibc 2.32-16.ph4 fixed in 2.32-18.ph4 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2024-33602 | NONE0 | glibc 2.32-16.ph4 fixed in 2.32-18.ph4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-41080 | NONE0 | expat-libs 2.4.9-2.ph4 fixed in 2.8.0-1.ph4 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-6141 | NONE0 | ncurses-libs 6.2-6.ph4 fixed in 6.5-1.ph4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-70873 | NONE0 | sqlite-libs 3.38.5-4.ph4 fixed in 3.38.5-7.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-33540 | NONE0 | github.com/distribution/distribution v2.8.2+incompatible No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-51744 | NONE0 | github.com/golang-jwt/jwt/v4 v4.2.0 fixed in 4.5.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-24515 | NONE0 | expat-libs 2.4.9-2.ph4 fixed in 2.7.4-1.ph4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-27139 | NONE0 | stdlib v1.21.9 fixed in 1.25.8, 1.26.1 | 0.2% Theoretical Threat | Not Applicable |
| BDSA-2026-9096 | NONE0 | curl 8.1.2-8.ph4 fixed in 8.20.0-1.ph4 | — | Not Applicable |
| CVE-2025-0167 | NONE0 | curl 8.1.2-8.ph4 fixed in 8.12.0-1.ph4 | 0.7% Theoretical Threat | Not Applicable |
| BDSA-2026-9096 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.20.0-1.ph4 | — | Not Applicable |
| CVE-2025-0167 | NONE0 | curl-libs 8.1.2-8.ph4 fixed in 8.12.0-1.ph4 | 0.7% Theoretical Threat | Not Applicable |
| BDSA-2025-0719 | NONE0 | krb5 1.17-10.ph4 fixed in 1.17-15.ph4 | — | Not Applicable |
| CVE-2025-7709 | NONE0 | sqlite-libs 3.38.5-4.ph4 fixed in 3.38.5-6.ph4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-24358 | NONE0 | github.com/gorilla/csrf v1.6.2 fixed in 1.7.3 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-47909 | NONE0 | github.com/gorilla/csrf v1.6.2 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-2303 | NONE0 | go.mongodb.org/mongo-driver v1.7.0 fixed in 1.17.7 | 0.2% Theoretical Threat | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.20.0 No fix yet | — | Not Applicable |
| CVE-2026-46600 | NONE0 | golang.org/x/net v0.21.0 fixed in 0.56.0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.17.0 fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56852 | NONE0 | golang.org/x/text v0.14.0 fixed in 0.39.0 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.58.3 fixed in 1.82.1 | — | Not Applicable |
| CVE-2025-0913 | NONE0 | stdlib v1.21.9 fixed in 1.23.10, 1.24.4 | 0.2% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.