Known vulnerabilities in OpenSSL
Vendor:
OpenSSL Software Foundation
Software:
OpenSSL
Software CPE:
cpe:2.3:a:openssl_software_foundation:openssl:*:*:*:*:*:*:*:*
Website:
https://www.openssl.org
Total vulnerabilities:
243
Public exploits:
26
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
1.0.2zs
1.1.1zj
3.0.23
3.4.8
3.5.9
3.6.5
4.0.3
1.0.2zr
1.1.1zi
4.0.2
3.6.4
3.5.8
3.4.7
3.0.22
1.1.1zh
1.0.2zq
4.0.1
3.6.3
3.5.7
3.4.6
3.0.21
4.0.0
1.0.2zp
1.0.2zo
1.1.1zg
1.1.1zf
3.6.2
3.5.6
3.4.5
3.3.7
3.0.20
1.0.2zn
1.1.1ze
3.0.19
3.3.6
3.4.4
3.5.5
3.6.1
3.6.0
1.1.1zd
1.0.2zm
1.1.1zc
3.5.4
3.4.3
3.3.5
3.2.6
3.0.18
3.5.3
3.5.2
3.5.1
3.4.2
3.3.4
3.2.5
3.0.17
3.5.0
1.0.2zl
1.1.1zb
3.4.1
3.3.3
3.2.4
3.1.8
3.0.16
3.4.0
1.1.1za
1.1.1z
1.0.2zk
3.3.2
3.2.3
3.1.7
3.0.15
1.1.1y
3.3.1
3.2.2
3.1.6
3.0.14
3.3.0
1.0.2zj
1.1.1x
3.2.1
3.1.5
3.0.13
3.2.0
3.1.4
3.0.12
3.1.3
3.0.11
1.1.1w
1.0.2zi
1.1.1v
3.1.2
3.0.10
1.0.2zh
1.1.1u
3.1.1
3.0.9
3.1.0
1.0.2zg
3.0.8
1.1.1t
3.0.7
1.1.1s
3.0.6
1.1.1r
3.0.5
1.1.1q
3.0.4
1.0.2zf
1.1.1p
1.0.2ze
1.1.1o
3.0.3
1.0.2zc
1.0.2zb
1.0.2zd
3.0.2
1.1.1n
1.1.1m
3.0.1
3.0.0
1.0.2za
1.1.1l
1.1.1k
1.0.2y
1.1.1j
1.0.2x
1.1.1i
1.1.1h
1.0.2w
1.0.2v
1.1.1g
1.1.1f
1.1.1e
1.0.2u
1.1.1d
1.1.0l
1.0.2t
0.9.8f-5
0.9.8f-8
0.9.8f-4
0.9.8f-7
0.9.8f-6
0.9.8f-9
0.9.8f-3
0.9.8f-2
0.9.8f-1
0.9.8g-4
0.9.8c-8
0.9.8g-7
0.9.8g-9
0.9.8g-3
0.9.8c-7
0.9.8g-6
0.9.8g-5
0.9.8c-9
0.9.8g-8
0.9.8c-3
0.9.8g-2
0.9.8c-6
0.9.8g-1
0.9.8c-5
0.9.8c-2
0.9.8c-1
0.9.8c-4
0.9.8d-7
0.9.8d-6
0.9.8d-9
0.9.8d-8
0.9.8d-2
0.9.8d-5
0.9.8d-4
0.9.8d-1
0.9.8d-3
0.9.8e-6
0.9.8e-9
0.9.8e-5
0.9.8e-8
0.9.8e-7
0.9.8e-1
0.9.8e-4
0.9.8e-3
0.9.8e-2
0.9.7a-2
0.9.6b-3
0.9.6-15
1.0.1e-25.el7
1.1.1c
1.1.0k
1.0.2s
1.0.0t
0.9.8zh
0.9.8zd
1.1.1b
1.0.2r
1.0.2q
1.1.0j
1.1.1a
1.0.2p
1.0.2o
1.1.0i
1.1.0h
1.1.1
1.0.2n
1.0.2m
1.1.0g
1.1.0f
1.0.2l
1.1.0e
1.1.0c
1.1.0d
1.0.2k
1.0.1u
1.0.2j
1.0.2i
1.1.0b
1.1.0a
1.1.0
0.9.8zg
1.0.0s
0.9.8zf
1.0.0r
0.9.8ze
1.0.0p
1.0.0q
1.0.0o
0.9.8zc
1.0.0n
0.9.8z
0.9.8zb
0.9.8za
1.0.0m
0.9.1b
0.9.0b
1.0.0f
1.0.0e
1.0.0h
1.0.0g
1.0.0d
1.0.0c
1.0.0j
1.0.0i
1.0.0l
1.0.0k
0.9.8y
0.9.8x
0.9.8w
0.9.8v
0.9.8u
1.0.0b
1.0.0a
1.0
1.0.0
0.9.8t
0.9.8s
0.9.8r
0.9.8q
0.9.8l
0.9.8k
0.9.8j
0.9.8i
0.9.8p
0.9.8o
0.9.8n
0.9.8m
0.9.8d
0.9.8h
0.9.8g
0.9.8f
0.9.8e
0.9.7m
0.9.7l
0.9.7j
0.9.7k
0.9.7h
0.9.7i
0.9.8c
0.9.8a
0.9.8b
0.9.8
0.9.7g
0.9.7f
0.9.7e
0.9.3a
0.9.7d
0.9.5a
0.9.2b
0.9.1c
0.9.3
0.9.5
0.9.4
1.0.2g
1.0.2f
1.0.2e
1.0.2d
1.0.2c
1.0.2b
1.0.2a
1.0.2
1.0.1t
1.0.1s
1.0.1r
1.0.1q
1.0.1p
1.0.1o
1.0.1n
1.0.1m
1.0.1l
1.0.1k
1.0.1j
1.0.1i
1.0.1h
1.0.1g
1.0.1f
1.0.1e
1.0.1d
1.0.1c
1.0.1b
1.0.1a
1.0.1
0.9.6m
0.9.6j
0.9.6i
0.9.6h
0.9.6g
0.9.6f
0.9.7
0.9.7a
0.9.7b
0.9.7c
0.9.6k
0.9.6l
0.9.6e
0.9.6
0.9.6a
0.9.6b
0.9.6c
0.9.6d
1.0.2h
Vulnerabilities (243)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU152952 - Use After Free CVE-2026-84783 |
CWE-416 | Medium | 4.0.3 | 30.09.2026 |
SB2026093079 |
||
| #VU152953 - Allocation of Resources Without Limits or Throttling CVE-2026-35189 |
CWE-770 | Medium | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093091 SB20261001103 and 5 more |
||
| #VU152954 - Expected Behavior Violation CVE-2026-35191 |
CWE-440 | Low | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093091 SB20261001112 and 1 more |
||
| #VU152955 - Inefficient Algorithmic Complexity CVE-2026-42772 |
CWE-407 | Low | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093091 SB2026100195 |
||
| #VU152956 - Information Exposure Through Timing Discrepancy CVE-2026-54872 |
CWE-208 | Medium | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093091 SB20261001103 and 5 more |
||
| #VU152957 - Allocation of Resources Without Limits or Throttling CVE-2026-54873 |
CWE-770 | Medium | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093091 SB2026100195 |
||
| #VU152958 - Information Exposure Through Timing Discrepancy CVE-2026-54875 |
CWE-208 | Medium | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093091 SB20261001112 and 1 more |
||
| #VU152959 - Out-of-bounds write CVE-2026-72897 |
CWE-787 | Medium | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093091 SB20261001112 and 1 more |
||
| #VU152960 - Allocation of Resources Without Limits or Throttling CVE-2026-75804 |
CWE-770 | Medium | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093091 SB20261001112 and 1 more |
||
| #VU152961 - NULL Pointer Dereference CVE-2026-75805 |
CWE-476 | Low | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093091 SB20261001112 and 4 more |
||
| #VU152962 - Improper Validation of Specified Quantity in Input CVE-2026-75806 |
CWE-1284 | Low | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093091 SB20261001112 and 4 more |
||
| #VU152963 - Information Exposure Through Timing Discrepancy CVE-2026-77696 |
CWE-208 | Medium | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093091 SB20261001103 and 5 more |
||
| #VU152964 - Allocation of Resources Without Limits or Throttling CVE-2026-84784 |
CWE-770 | Medium | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093091 SB20261001112 and 1 more |
||
| #VU152944 - Out-of-bounds read CVE-2026-84782 |
CWE-125 | Medium | 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3 | 30.09.2026 |
SB2026093079 SB2026093080 SB2026093091 and 7 more |
||
| #VU145416 - Double Free CVE-2026-18798 |
CWE-415 | Medium | 3.5.8, 3.6.4, 4.0.2 | 26.08.2026 |
SB2026082627 SB2026082629 SB2026082636 and 4 more |
||
| #VU145417 - Out-of-bounds write CVE-2026-63072 |
CWE-787 | Medium | 1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4, 4.0.2 | 26.08.2026 |
SB2026082627 SB2026082629 SB2026082636 and 32 more |
||
| #VU145418 - NULL Pointer Dereference CVE-2026-63076 |
CWE-476 | Medium | 3.0.22, 3.4.7, 3.5.8, 3.6.4, 4.0.2 | 26.08.2026 |
SB2026082627 SB2026082629 SB2026082636 and 16 more |
||
| #VU145419 - NULL Pointer Dereference CVE-2026-14457 |
CWE-476 | Medium | 3.4.7, 3.5.8, 3.6.4, 4.0.2 | 26.08.2026 |
SB2026082627 SB2026082629 SB2026082636 and 6 more |
||
| #VU145420 - Asymmetric Resource Consumption (Amplification) CVE-2026-54874 |
CWE-405 | Medium | 1.0.2zr, 1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4, 4.0.2 | 26.08.2026 |
SB2026082627 SB2026082629 SB2026082636 and 23 more |
||
| #VU145421 - Use of Externally-Controlled Format String CVE-2026-63073 |
CWE-134 | Medium | 3.4.7, 3.5.8, 3.6.4, 4.0.2 | 26.08.2026 |
SB2026082627 SB2026082629 SB2026082636 and 4 more |
Showing elements 1 - 20 out of 243