Which package version actually fixes it
For twelve pieces of software that run on nearly every Linux server, the advisories that apply to each supported distribution, and the package version that fixes each one. The thing nobody puts in a single place, because each distribution publishes only its own half.
Why this exists
A CVE number is easy to look up and tells you almost nothing useful. What an administrator actually needs is the next step: on the distribution I am running, which package version has the fix, and how do I tell whether I have it. That answer lives in six different advisory trackers using four different version schemes, and it is why a CVE database lookup so often ends in a shrug.
Distributions backport fixes without changing the upstream version, so “OpenSSH 9.6 is old” is not a finding and the package revision after the dash is the part that decides. These pages carry the revision.
Distributions covered
The ones SecAI’s agent supports, each asked separately rather than assumed to match its family.
Software covered
Individual CVEs
Twenty that clear a bar: in CISA’s Known Exploited catalogue, or with a name people actually search for, and affecting a package that runs on real Linux servers. Each says what the bug is, what an attacker gets out of it, and the conditions under which it does not apply to you, because an old package version and a real exposure are different things.
Nothing published before 2023 is here, and that is a correctness rule rather than an editorial one. Debian’s tracker records the version a fix first landed in, which for an older flaw predates every release on this site: a Heartbleed page would print “Debian 12: fixed in 1.0.1g-1”, which is what the advisory says and reads as an upgrade target for a release that shipped patched three major versions later. There is also no per-CVE page for the Linux kernel, where Debian alone carries three thousand advisories and the question “which version fixes it” has a different shape.
What is deliberately not here
- A page for every CVE. There were 48,185 CVEs published in 2025 alone, six sites already mirror that database, and a page per row would be a worse copy of theirs. Twelve pieces of software and twenty CVEs, written properly, is worth more than twenty thousand generated pages.
- A count of affected servers. SecAI monitors a small fleet. A percentage drawn from it would be arithmetic on a sample too small to mean anything, and dressing that as a measurement is exactly what these pages exist not to do.
- Upstream advisory text. Ubuntu’s advisory data is share-alike licensed. Every word of writing here is ours, and the version data is cited as what it is.
Or just find out what you are running
One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them. It changes nothing.