CVE database for Linux servers

Curated vulnerabilities affecting the software you run on production servers — with remediation steps per distro, WAF mitigations, and Defensia detection mapping.

Actively exploited

CVE-2025-49113criticalCVSS 9.9Jun 2, 2025PHP · Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by au…
CVE-2025-24016criticalCVSS 9.9Feb 10, 2025Python · Wazuh is a free and open source platform used for threat prevention, detection, and respon…
CVE-2026-39987criticalCVSS 9.8Apr 9, 2026Python · marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerabi…
CVE-2026-48939criticalCVSS 9.8Jun 20, 2026PHP · A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files …
CVE-2026-48908criticalCVSS 9.8Jun 20, 2026PHP · A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbit…
CVE-2024-56145criticalCVSS 9.8Dec 18, 2024PHP · Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web …
CVE-2026-48907criticalCVSS 9.8Jun 5, 2026PHP · A vulnerability in the JCE editor extension for Joomla allows the creation of new editor p…
CVE-2026-45247criticalCVSS 9.8May 26, 2026PHP · Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object…
CVE-2024-4577criticalCVSS 9.8Jun 9, 2024PHP · In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using A…
CVE-2026-33017criticalCVSS 9.8Mar 20, 2026Python · Langflow is a tool for building and deploying AI-powered agents and workflows. In versions…
CVE-2025-0108criticalCVSS 9.1Feb 12, 2025PHP · An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthentica…
CVE-2024-38475criticalCVSS 9.1Jul 1, 2024Apache · Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows…
CVE-2024-53197highCVSS 7.8Dec 27, 2024Kernel · In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix …
CVE-2024-53104highCVSS 7.8Dec 2, 2024Kernel · In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip…
CVE-2024-36971highCVSS 7.8Jun 10, 2024Kernel · In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negati…
CVE-2024-53150highCVSS 7.1Dec 24, 2024Kernel · In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix …
CVE-2024-50302mediumCVSS 5.5Nov 19, 2024Kernel · In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initi…

By software