Known vulnerabilities in OpenBSD

Vendor: OpenBSD
Software: OpenBSD
Software CPE: cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*
Total vulnerabilities: 148
Public exploits: 11
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenBSD OpenBSD is affected by 148 known vulnerabilities: 2 critical, 8 high, 39 medium, 99 low Critical High Medium Low

Vulnerabilities (148)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU131174 - Improper input validation
CWE-20 Medium
No
No
- 12.05.2026 SB2026051272
#VU131173 - Improper input validation
CWE-20 Medium
No
No
- 12.05.2026 SB2026051271
#VU128246 - Insufficient Entropy
CVE-2026-41080
CWE-331 Low
No
No
- 27.04.2026 SB20260427193
SB2026051240
SB2026051270
and 14 more
#VU126141 - NULL Pointer Dereference
CWE-476 Low
No
No
- 15.04.2026 SB2026041563
#VU126140 - Improper input validation
CWE-20 Low
No
No
- 15.04.2026 SB2026041563
#VU125987 - Integer underflow
CVE-2026-33999
CWE-191 Low
No
No
- 14.04.2026 SB20260414114
SB2026041559
SB2026041592
and 36 more
#VU125988 - Out-of-bounds read
CVE-2026-34000
CWE-125 Low
No
No
- 14.04.2026 SB20260414114
SB2026041559
SB2026041592
and 27 more
#VU125989 - Use After Free
CVE-2026-34001
CWE-416 Low
No
No
- 14.04.2026 SB20260414114
SB2026041559
SB2026041592
and 36 more
#VU125990 - Out-of-bounds read
CVE-2026-34002
CWE-125 Low
No
No
- 14.04.2026 SB20260414114
SB2026041559
SB2026041592
and 27 more
#VU125991 - Out-of-bounds read
CVE-2026-34003
CWE-125 Low
No
No
- 14.04.2026 SB20260414114
SB2026041559
SB2026041592
and 36 more
#VU124016 - Resource Management Errors
CWE-399 Low
No
No
- 14.03.2026 SB2026031403
#VU123884 - Integer overflow
CVE-2026-23865
CWE-190 Medium
No
No
- 11.03.2026 SB2026031140
SB2026031141
SB2026031523
and 51 more
#VU123615 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 Low
No
No
- 06.03.2026 SB2026030635
#VU123614 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 Low
No
No
- 06.03.2026 SB2026030634
#VU123341 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-362 Low
No
No
- 28.02.2026 SB2026022821
#VU122268 - Integer overflow
CVE-2026-25210
CWE-190 High
No
No
- 03.02.2026 SB2026020364
SB20260205121
SB2026020611
and 22 more
#VU122267 - NULL Pointer Dereference
CVE-2026-24515
CWE-476 Medium
No
No
- 03.02.2026 SB2026020364
SB2026020367
SB2026020368
and 18 more
#VU122239 - Use After Free
CWE-416 Medium
No
No
- 02.02.2026 SB20260202118
#VU15925 - NULL Pointer Dereference
CVE-2018-15859
CWE-476 Low
No
No
- 16.11.2018 SB2018073020
SB2018111704
SB2018103009
and 5 more
#VU15753 - Improper input validation
CVE-2018-15853
CWE-20 Low
No
No
- 07.11.2018 SB2018073020
SB2018111704
SB2018103009
and 7 more


Showing elements 1 - 20 out of 148