Known vulnerabilities in OpenSSL - page 3

Software: OpenSSL
Software CPE: cpe:2.3:a:openssl_software_foundation:openssl:*:*:*:*:*:*:*:*
Total vulnerabilities: 243
Public exploits: 26
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenSSL OpenSSL is affected by 243 known vulnerabilities: 2 critical, 15 high, 146 medium, 80 low Critical High Medium Low

Vulnerabilities (243)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU134271 - Improper input validation
CVE-2026-34182
CWE-20 High
No
No
3.0.21, 3.4.6, 3.5.7, 3.6.3, 4.0.1 10.06.2026 SB20260610118
SB20260610119
SB20260610122
and 25 more
#VU134272 - Allocation of Resources Without Limits or Throttling
CVE-2026-34183
CWE-770 Medium
No
No
3.4.6, 3.5.7, 3.6.3, 4.0.1 10.06.2026 SB20260610118
SB20260610119
SB20260610123
and 14 more
#VU134287 - Improper Verification of Cryptographic Signature
CVE-2026-45446
CWE-347 Medium
No
No
3.0.21, 3.4.6, 3.5.7, 3.6.3, 4.0.1 10.06.2026 SB20260610118
SB20260610119
SB20260610123
and 19 more
#VU125562 - Unchecked Return Value
CVE-2026-31790
CWE-252 Medium
No
No
3.0.20, 3.3.7, 3.4.5, 3.5.6, 3.6.2 09.04.2026 SB2026040943
SB2026040944
SB2026040945
and 30 more
#VU125563 - Out-of-bounds read
CVE-2026-28386
CWE-125 Low
No
No
3.6.2 09.04.2026 SB2026040943
#VU125564 - Use After Free
CVE-2026-28387
CWE-416 High
No
No
1.1.1zg, 3.0.20, 3.3.7, 3.4.5, 3.5.6, 3.6.2 09.04.2026 SB2026040943
SB2026040944
SB2026040945
and 30 more
#VU125565 - NULL Pointer Dereference
CVE-2026-28388
CWE-476 Low
No
No
1.0.2zp, 1.1.1zg, 3.0.20, 3.3.7, 3.4.5, 3.5.6, 3.6.2 09.04.2026 SB2026040943
SB2026040944
SB2026040945
and 39 more
#VU125566 - NULL Pointer Dereference
CVE-2026-28389
CWE-476 Medium
No
No
1.0.2zp, 1.1.1zg, 3.0.20, 3.3.7, 3.4.5, 3.5.6, 3.6.2 09.04.2026 SB2026040943
SB2026040944
SB2026040945
and 32 more
#VU125567 - NULL Pointer Dereference
CVE-2026-28390
CWE-476 Medium
No
No
1.0.2zp, 1.1.1zg, 3.0.20, 3.3.7, 3.4.5, 3.5.6, 3.6.2 09.04.2026 SB2026040943
SB2026040944
SB2026040992
and 52 more
#VU125568 - Heap-based Buffer Overflow
CVE-2026-31789
CWE-122 Medium
No
No
3.0.20, 3.3.7, 3.4.5, 3.5.6, 3.6.2 09.04.2026 SB2026040943
SB2026040944
SB2026040945
and 23 more
#VU125561 - Always-Incorrect Control Flow Implementation
CVE-2026-2673
CWE-670 Low
No
No
3.5.6, 3.6.2 09.04.2026 SB2026040943
SB2026040944
SB20260409112
and 5 more
#VU122083 - Type confusion
CVE-2025-69420
CWE-843 Medium
No
No
1.1.1ze, 3.0.19, 3.3.6, 3.4.4, 3.5.5, 3.6.1 27.01.2026 SB2026012785
SB2026012791
SB2026012792
and 49 more
#VU122082 - Out-of-bounds write
CVE-2025-69419
CWE-787 Low
No
No
1.1.1ze, 3.0.19, 3.3.6, 3.4.4, 3.5.5, 3.6.1 27.01.2026 SB2026012785
SB2026012791
SB2026012792
and 69 more
#VU122081 - Cleartext Transmission of Sensitive Information
CVE-2025-69418
CWE-319 Low
No
No
1.1.1ze, 3.0.19, 3.3.6, 3.4.4, 3.5.5, 3.6.1 27.01.2026 SB2026012785
SB2026012791
SB2026012792
and 47 more
#VU122080 - Out-of-bounds write
CVE-2025-68160
CWE-787 Medium
No
No
1.0.2zn, 1.1.1ze, 3.0.19, 3.3.6, 3.4.4, 3.5.5, 3.6.1 27.01.2026 SB2026012785
SB2026012791
SB2026012792
and 49 more
#VU122079 - Resource exhaustion
CVE-2025-66199
CWE-400 Medium
No
No
3.3.6, 3.4.4, 3.5.5, 3.6.1 27.01.2026 SB2026012785
SB2026012791
SB2026012792
and 18 more
#VU122078 - Numeric Truncation Error
CVE-2025-15469
CWE-197 Low
No
No
3.5.5, 3.6.1 27.01.2026 SB2026012785
SB2026012791
SB2026012792
and 15 more
#VU122077 - NULL Pointer Dereference
CVE-2025-15468
CWE-476 Medium
No
No
3.3.6, 3.4.4, 3.5.5, 3.6.1 27.01.2026 SB2026012785
SB2026012791
SB2026012792
and 19 more
#VU122076 - Stack-based buffer overflow
CVE-2025-15467
CWE-121 High
Available
No
3.0.19, 3.3.6, 3.4.4, 3.5.5, 3.6.1 27.01.2026 SB2026012785
SB2026012791
SB2026012792
and 67 more
#VU122075 - Stack-based buffer overflow
CVE-2025-11187
CWE-121 Medium
No
No
3.4.4, 3.5.5, 3.6.1 27.01.2026 SB2026012785
SB2026012791
SB2026012792
and 20 more


Showing elements 41 - 60 out of 243