r
rpm
Security Risk Profile
28
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 35 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 6, 2006 to present
35
Total CVEs
15
Critical+High
0
Exploited
6
Unpatched
Threat Assessment
Avg CVSS
6.3
Base severity
Avg EPSS
1%
Exploit probability
Unpatched
6
Critical/High
Risk Level
28/100
low
🆕 2Fresh (<7d)📈 2 in Last 30 Days
Severity Distribution
Critical
3High
12Medium
19Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
Buffer Overflow
5
2
Command Injection
3
3
Input Validation
3
4
OS Command Injection
2
5
Integer Overflow
2
Most Affected Products
1. RPM RPM636
2. rpm rpm395
3. redhat/rpm15
4. Fedoraproject Fedora12
5. redhat Enterprise Linux11
Recent Vulnerabilities
See more →CVE-2026-95521
CVSS 7.8EPSS 1%high
Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm
Sep 22, 2026🔧 No Patch
REDHAT-BUG-2537812
CVSS 4.0medium
Sep 22, 2026🔧 No Patch
CVE-2026-44605
CVSS 5.5medium
Rpm: heap buffer overflow in ndb slot table parsing
May 28, 2026
REDHAT-BUG-2482481
CVSS 1.0low
May 28, 2026🔧 No Patch
REDHAT-BUG-2460967
CVSS 4.0medium
Apr 23, 2026🔧 No Patch
REDHAT-BUG-2440357
CVSS 4.0medium
Feb 17, 2026🔧 No Patch
CVE-2024-1929
CVSS 8.4high
Local Root Exploit via Configuration Dictionary
Mar 4, 2024
CVE-2021-35939
CVSS 6.7medium
May 24, 2021
CVE-2021-35937
CVSS 6.4medium
May 24, 2021
CVE-2021-35938
CVSS 6.7medium
May 24, 2021
Monitor rpm in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.