Browse vulnerabilities
155 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2014-0160 | Act now | 100.0% | — | ● | The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension pac… |
| CVE-2026-74899 | High | 0.5% | 9.8 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPl… | |
| CVE-2026-32253 | High | 0.3% | 9.8 | Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.14… | |
| CVE-2025-15467 | Medium | 48.2% | 8.8 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously cra… | |
| CVE-2026-45447 | Medium | 3.6% | 8.8 | Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-aft… | |
| CVE-2024-1394 | Medium | 1.5% | 7.5 | A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might … | |
| CVE-2025-5987 | Medium | 1.5% | 8.1 | A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an … | |
| CVE-2026-18798 | Medium | 1.5% | 7.5 | Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel … | |
| CVE-2026-63076 | Medium | 1.4% | 7.5 | Issue summary: OpenSSL CMP password based protection verification only checks whether the … | |
| CVE-2026-42764 | Medium | 1.2% | 7.5 | Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL po… | |
| CVE-2026-34183 | Medium | 1.0% | 7.5 | Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by floodin… | |
| CVE-2026-31790 | Medium | 1.0% | 7.5 | Issue summary: Applications using RSASVE key encapsulation to establish a secret encryptio… | |
| CVE-2026-34180 | Medium | 1.0% | 7.5 | Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whos… | |
| CVE-2026-14457 | Medium | 1.0% | 7.5 | Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) ena… | |
| CVE-2026-63073 | Medium | 0.9% | 9.8 | Issue summary: OpenSSL CMP response validation passed an unexpected response sender distin… | |
| CVE-2026-80229 | Medium | 0.9% | 7.5 | When performing transfers via libcurl’s multi interface, pooled TLS connections can outliv… | |
| CVE-2026-28388 | Medium | 0.9% | 7.5 | Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed… | |
| CVE-2026-15981 | Medium | 0.8% | 9.8 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication B… | |
| CVE-2026-28389 | Medium | 0.8% | 7.5 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecip… | |
| CVE-2026-28390 | Medium | 0.8% | 7.5 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportR… | |
| CVE-2026-7383 | Medium | 0.8% | 8.1 | Issue summary: A signed integer overflow when sizing the destination buffer for Unicode ou… | |
| CVE-2026-14456 | Medium | 0.7% | 7.5 | Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Init… | |
| CVE-2026-9076 | Medium | 0.7% | 7.5 | Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes a… | |
| CVE-2026-27459 | Medium | 0.7% | 9.8 | pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and p… | |
| CVE-2026-45445 | Medium | 0.7% | 7.5 | Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher… | |
| CVE-2026-63072 | Medium | 0.7% | 7.5 | Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying… | |
| CVE-2026-28387 | Medium | 0.7% | 8.1 | Issue summary: An uncommon configuration of clients performing DANE TLSA-based server auth… | |
| CVE-2026-34182 | Medium | 0.6% | 9.1 | Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient… | |
| CVE-2026-66033 | Medium | 0.6% | 7.5 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer und… | |
| CVE-2026-33895 | Medium | 0.5% | 7.5 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in… | |
| CVE-2026-54874 | Medium | 0.5% | 7.5 | Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress… | |
| CVE-2026-42765 | Medium | 0.5% | 7.5 | Issue summary: When a partial-chain certificate verification is enabled together with OCSP… | |
| CVE-2026-50010 | Medium | 0.5% | 7.5 | Netty is a network application framework for development of protocol servers and clients. … | |
| CVE-2026-81690 | Medium | 0.5% | 7.3 | openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify… | |
| CVE-2026-63075 | Medium | 0.5% | 7.5 | Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-e… | |
| CVE-2026-74872 | Medium | 0.5% | 9.8 | openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in… | |
| CVE-2026-17510 | Medium | 0.4% | 7.5 | Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in p… | |
| CVE-2026-81707 | Medium | 0.4% | 9.8 | openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity docume… | |
| CVE-2026-74895 | Medium | 0.4% | 9.8 | openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default pr… | |
| CVE-2026-74878 | Medium | 0.4% | 9.8 | openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force p… | |
| CVE-2026-81721 | Medium | 0.4% | 7.5 | openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metad… | |
| CVE-2026-13447 | Medium | 0.4% | 9.8 | The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery… | |
| CVE-2026-74886 | Medium | 0.4% | 9.8 | openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where … | |
| CVE-2026-74894 | Medium | 0.4% | 9.8 | openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify… | |
| CVE-2026-81699 | Medium | 0.4% | 7.5 | openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function co… | |
| CVE-2026-59825 | Medium | 0.3% | 7.4 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.1… | |
| CVE-2026-81692 | Medium | 0.3% | 7.5 | openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-… | |
| CVE-2026-81693 | Medium | 0.3% | 7.5 | openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads befor… | |
| CVE-2026-58102 | Medium | 0.3% | 9.1 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a … | |
| CVE-2026-74896 | Medium | 0.3% | 9.8 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the Danger… |
Page 1 of 4
Next →