Debian vulnerabilities: known CVEs & security history
Debian · Operating System · 2000 tracked CVEs · 18 actively exploited · updated June 2026 · what is a CVE? →
This is the full list of known vulnerabilities (CVEs) across all Debian release lines — 2000 in total, with 18 actively exploited in the wild. A CVE here doesn't mean your version is affected — check Debian's current status and the safe version to run.
Known Debian CVEs
Actively-exploited and most-severe first. Showing the top 80 of 2000. Open any CVE for full details.
| CVE | Severity | CVSS | EPSS | Year |
|---|---|---|---|---|
| CVE-2016-8735⚡ exploited | critical | 9.8 | 90% | 2017 |
| CVE-2016-3427⚡ exploited | critical | 9.8 | 92% | 2016 |
| CVE-2015-2590⚡ exploited | critical | 9.8 | 26% | 2015 |
| CVE-2014-7169⚡ exploited | critical | 9.8 | 100% | 2014 |
| CVE-2014-6271⚡ exploited | critical | 9.8 | 100% | 2014 |
| CVE-2012-0507⚡ exploited | critical | 9.8 | 98% | 2012 |
| CVE-2012-1823⚡ exploited | critical | 9.8 | 100% | 2012 |
| CVE-2010-4344⚡ exploited | critical | 9.8 | 72% | 2010 |
| CVE-2009-1151⚡ exploited | critical | 9.8 | 95% | 2009 |
| CVE-2016-1646⚡ exploited | high | 8.8 | 45% | 2016 |
| CVE-2013-1690⚡ exploited | high | 8.8 | 69% | 2013 |
| CVE-2016-3714⚡ exploited | high | 8.4 | 97% | 2016 |
| CVE-2010-4345⚡ exploited | high | 7.8 | 18% | 2010 |
| CVE-2016-0752⚡ exploited | high | 7.5 | 96% | 2016 |
| CVE-2014-0160⚡ exploited | high | 7.5 | 100% | 2014 |
| CVE-2016-5195⚡ exploited | high | 7 | 84% | 2016 |
| CVE-2013-1675⚡ exploited | medium | 6.5 | 7% | 2013 |
| CVE-2014-0196⚡ exploited | medium | 5.5 | 22% | 2014 |
| CVE-2015-8104 | critical | 10 | 3% | 2015 |
| CVE-2017-7865 | critical | 9.8 | 3% | 2017 |
| CVE-2017-7863 | critical | 9.8 | 3% | 2017 |
| CVE-2015-6674 | critical | 9.8 | 2% | 2017 |
| CVE-2016-1908 | critical | 9.8 | 14% | 2017 |
| CVE-2014-5008 | critical | 9.8 | 4% | 2017 |
| CVE-2017-5511 | critical | 9.8 | 5% | 2017 |
| CVE-2017-5897 | critical | 9.8 | 5% | 2017 |
| CVE-2017-5522 | critical | 9.8 | 5% | 2017 |
| CVE-2016-10195 | critical | 9.8 | 7% | 2017 |
| CVE-2016-8863 | critical | 9.8 | 8% | 2017 |
| CVE-2017-5946 | critical | 9.8 | 3% | 2017 |
| CVE-2016-1245 | critical | 9.8 | 4% | 2017 |
| CVE-2016-2148 | critical | 9.8 | 15% | 2017 |
| CVE-2016-7447 | critical | 9.8 | 4% | 2017 |
| CVE-2016-7446 | critical | 9.8 | 4% | 2017 |
| CVE-2017-5611 | critical | 9.8 | 10% | 2017 |
| CVE-2017-5205 | critical | 9.8 | 4% | 2017 |
| CVE-2017-5204 | critical | 9.8 | 6% | 2017 |
| CVE-2017-5203 | critical | 9.8 | 4% | 2017 |
| CVE-2017-5202 | critical | 9.8 | 4% | 2017 |
| CVE-2016-9636 | critical | 9.8 | 9% | 2017 |
| CVE-2016-9635 | critical | 9.8 | 9% | 2017 |
| CVE-2016-9634 | critical | 9.8 | 9% | 2017 |
| CVE-2016-10160 | critical | 9.8 | 7% | 2017 |
| CVE-2016-2090 | critical | 9.8 | 3% | 2017 |
| CVE-2013-1430 | critical | 9.8 | 1% | 2016 |
| CVE-2016-9427 | critical | 9.8 | 4% | 2016 |
| CVE-2016-7117 | critical | 9.8 | 24% | 2016 |
| CVE-2016-7161 | critical | 9.8 | 6% | 2016 |
| CVE-2016-1243 | critical | 9.8 | 5% | 2016 |
| CVE-2016-5180 | critical | 9.8 | 9% | 2016 |
| CVE-2016-7568 | critical | 9.8 | 5% | 2016 |
| CVE-2016-4303 | critical | 9.8 | 7% | 2016 |
| CVE-2016-6525 | critical | 9.8 | 4% | 2016 |
| CVE-2016-6354 | critical | 9.8 | 9% | 2016 |
| CVE-2015-8871 | critical | 9.8 | 3% | 2016 |
| CVE-2016-6662 | critical | 9.8 | 68% | 2016 |
| CVE-2015-8949 | critical | 9.8 | 4% | 2016 |
| CVE-2014-9906 | critical | 9.8 | 6% | 2016 |
| CVE-2016-5772 | critical | 9.8 | 10% | 2016 |
| CVE-2016-5771 | critical | 9.8 | 15% | 2016 |
| CVE-2016-5770 | critical | 9.8 | 7% | 2016 |
| CVE-2016-4610 | critical | 9.8 | 5% | 2016 |
| CVE-2016-4609 | critical | 9.8 | 5% | 2016 |
| CVE-2016-5008 | critical | 9.8 | 4% | 2016 |
| CVE-2016-3955 | critical | 9.8 | 26% | 2016 |
| CVE-2016-5118 | critical | 9.8 | 49% | 2016 |
| CVE-2016-0749 | critical | 9.8 | 9% | 2016 |
| CVE-2016-5108 | critical | 9.8 | 25% | 2016 |
| CVE-2015-7695 | critical | 9.8 | 3% | 2016 |
| CVE-2014-9746 | critical | 9.8 | 3% | 2016 |
| CVE-2016-0718 | critical | 9.8 | 13% | 2016 |
| CVE-2016-4544 | critical | 9.8 | 7% | 2016 |
| CVE-2015-4643 | critical | 9.8 | 17% | 2016 |
| CVE-2016-4024 | critical | 9.8 | 6% | 2016 |
| CVE-2016-2195 | critical | 9.8 | 7% | 2016 |
| CVE-2016-4422 | critical | 9.8 | 2% | 2016 |
| CVE-2015-0857 | critical | 9.8 | 5% | 2016 |
| CVE-2016-4002 | critical | 9.8 | 6% | 2016 |
| CVE-2016-3074 | critical | 9.8 | 37% | 2016 |
| CVE-2015-8779 | critical | 9.8 | 6% | 2016 |
1920 older / lower-severity CVEs not shown — see Debian's full record.
Is my Debian version affected?
The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.
Check your Debian version → · Monitor Debian for new CVEs →
Debian vulnerabilities — frequently asked
How many known vulnerabilities does Debian have?
IsItPatched tracks 2000 CVEs for Debian, 18 of which are actively exploited (CISA KEV). 112 are critical-severity and 798 high-severity. These span every release line — what matters is whether the version you run is affected.
Does Debian have any actively-exploited vulnerabilities?
Yes — 18 Debian CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild (1 linked to ransomware). Patch these as a priority.
What is the most severe Debian vulnerability?
Among tracked issues, CVE-2016-8735 (CRITICAL, CVSS 9.8), which is actively exploited, ranks highest.
Is Debian safe to use?
It depends on the version. The latest supported Debian release (13.5) clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.
CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Debian security status · Debian end-of-life · actively-exploited CVEs. Always verify against Debian's advisories — see our disclaimer.