rpm-software-management
Security Risk Profile
62
/100
highSecurity Risk Score
Comprehensive risk assessment based on 3 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 30, 2023 to present
3
Total CVEs
2
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
7.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
62/100
high
Severity Distribution
Critical
1High
1Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
Command Injection
1
2
OS Command Injection
1
3
Input Validation
1
4
Code Injection
1
Most Affected Products
1. Fedoraproject Extra Packages For Enterprise Linux3
2. Fedoraproject Fedora2
3. Rpm-software-management RPM1
4. dnf5 dnf5daemon-server1
5. Rpm-software-management Dnf51
Recent Vulnerabilities
See more →CVE-2026-44604
CVSS 7.0high
Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level directory name in popen() shell command
4/23/2026🔧 No Patch
CVE-2024-1930
CVSS 6.5medium
No Limit on Number of Open Sessions / Bad Session Close Behaviour
3/4/2024
CVE-2023-6395
CVSS 9.8EPSS 0%critical
Mock: privilege escalation for users that can access mock configuration
11/30/2023
Monitor rpm-software-management in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.