Where
AND
-Infinity
0

Vendor Risk Score

See how openssl compares to other vendors in security performance

View Risk Score →

OpenSSL OpenSSLHMAC zero-length tag forgery in EVP_DigestVerifyFinal

Risk 43
Severity
2.1
First published (updated )

OpenSSL ParseCRL_ExtensionsCRL critical extension bypass in ParseCRL_Extensions

Risk 27
Severity
1
First published (updated )

OpenSSL OpenSSLIncorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes Incorrect Tag Processi…

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLFFC-DH Peer Validation Uses Attacker-Supplied q

Risk 21
Severity
3.7
First published (updated )

OpenSSL OpenSSLFFC-DH Peer Validation Uses Attacker-Supplied q (CVE-2026-42770) Severity: Low Issue summary: When …

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenSSL OpenSSLMulti-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()

Risk 21
Severity
3.7
First published (updated )

OpenSSL OpenSSLNull Pointer Dereference

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLMulti-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() Multi-RecipientInfo …

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLNull Pointer Dereference

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLPKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys PKCS#12 Files with PBMAC1 Are Accepted …

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenSSL OpenSSLSeverity: Low Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element…

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLSeverity: Low Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) proces…

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLBuffer Overflow, Integer Overflow

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLSeverity: Low Issue summary: A type confusion vulnerability exists in the signature verification of…

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLNull Pointer Dereference

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenSSL OpenSSLNull Pointer Dereference

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLNull Pointer Dereference

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLThe trailing 1-15 bytes of a message may be exposed in cleartext on encryption and are not covered b…

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLThis out-of-bounds write can cause memory corruption which typically results in a crash, leading to …

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLAn attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU …

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenSSL OpenSSLA user signing or verifying files larger than 16MB with one-shot algorithms (such as Ed25519, Ed448,…

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLNull Pointer Dereference

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLSauter: Command Injection

Risk 16
Severity
2.7
First published (updated )

SAP NetWeaver AS JavaInformation Disclosure due to Outdated OpenSSL Version in SAP NetWeaver AS Java (Adobe Document Service)

Risk 23
Severity
3.4
First published (updated )

Nvidia NvContainerNVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an at…

Risk 14
Severity
2.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenSSL OpenSSLUse After Free

Risk 5
Severity
1
First published (updated )

pypi/cpythonCPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_pro…

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLIssue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client…

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSLPKCS12 structures contain PKCS7 ContentInfo fields. These fields are optional and can be NULL even i…

Risk 5
Severity
1
First published (updated )

OpenSSL OpenSSL-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 OpenSSL Security Advisory [31st July 2023] ========…

Risk 5
Severity
1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203