38 entries matching openssl — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-84975 | PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuT | HIGH | 7.4 | — | NVD | 2026-09-18 |
| CVE-2026-92939 | vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. | CRITICAL | 9.4 | 44%ile | NVD | 2026-09-17 |
| CVE-2026-90439 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL v | MEDIUM | 6.9 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-80229 | OpenSSL provider use-after-free | HIGH | 7.5 | 58%ile | Microsoft | 2026-09-08 |
| CVE-2026-78124 | strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of relea | LOW | 3.7 | 9%ile | Microsoft | 2026-09-08 |
| CVE-2026-80230 | OpenSSL pinning bypass | LOW | 3.7 | 46%ile | Microsoft | 2026-09-08 |
| CVE-2015-0204 | OSSN-0045: = Vulnerable clients allow a TLS protocol downgrade (FREAK)= | UNKNOWN | — | 100%ile | OpenStack | 2026-08-27 |
| CVE-2026-70454 | rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode | HIGH | 8.0 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-54874 | Excessive Memory Use Buffering DTLS Records for a Future Epoch | HIGH | 7.5 | 43%ile | Microsoft | 2026-08-11 |
| CVE-2026-63072 | Heap Buffer Overflow in CMS Key Unwrapping | HIGH | 7.5 | 51%ile | Microsoft | 2026-08-11 |
| CVE-2026-63075 | QUIC ACK-only Packet Retention Can Cause Memory Exhaustion | HIGH | 7.5 | 41%ile | Microsoft | 2026-08-11 |
| CVE-2026-63076 | Invalid Pointer Dereference in CMP Server via Crafted protectionAlg | HIGH | 7.5 | 70%ile | Microsoft | 2026-08-11 |
| CVE-2026-63073 | Untrusted Sender DN Used as Format String in CMP Response Validation | HIGH | 7.4 | 59%ile | Microsoft | 2026-08-11 |
| CVE-2026-14663 | PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext | MEDIUM | 6.5 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-53583 | libgit2: Inverted IP SubjectAltName Comparison in OpenSSL Backend | MEDIUM | 6.5 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-63074 | CMP Indefinite Cache Growth of ExtraCerts | MEDIUM | 5.9 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-59847 | Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification | MEDIUM | 5.9 | 27%ile | Microsoft | 2026-07-14 |
| CVE-2026-14355 | ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD | MEDIUM | 5.6 | 21%ile | Microsoft | 2026-07-14 |
| CVE-2026-34182 | CMS AuthEnvelopedData Processing May Accept Forged Messages | CRITICAL | 9.1 | 48%ile | Microsoft | 2026-06-09 |
| CVE-2026-45447 | Heap Use-After-Free in the PKCS7_verify() Function | HIGH | 8.8 | 89%ile | Microsoft | 2026-06-09 |
| CVE-2026-7383 | Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion | HIGH | 8.1 | 55%ile | Microsoft | 2026-06-09 |
| CVE-2026-34180 | Heap Buffer Over-read in ASN.1 Content Parsing | HIGH | 7.5 | 62%ile | Microsoft | 2026-06-09 |
| CVE-2026-34183 | Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler | HIGH | 7.5 | 63%ile | Microsoft | 2026-06-09 |
| CVE-2026-45445 | AES-OCB IV Ignored on EVP_Cipher() Path | HIGH | 7.5 | 52%ile | Microsoft | 2026-06-09 |
| CVE-2026-9076 | Out-of-Bounds Read in CMS Password-Based Decryption | HIGH | 7.5 | 52%ile | Microsoft | 2026-06-09 |
| CVE-2026-42766 | Possible NULL Dereference in Password-Based CMS Decryption | MEDIUM | 5.9 | 63%ile | Microsoft | 2026-06-09 |
| CVE-2026-42767 | NULL Pointer Dereference in CRMF EncryptedValue Decryption | MEDIUM | 5.9 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-42769 | Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate | MEDIUM | 5.3 | 34%ile | Microsoft | 2026-06-09 |
| CVE-2026-45446 | Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes | MEDIUM | 4.8 | 38%ile | Microsoft | 2026-06-09 |
| CVE-2026-42768 | Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() | LOW | 3.7 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-42770 | FFC-DH Peer Validation Uses Attacker-Supplied q | LOW | 3.7 | 42%ile | Microsoft | 2026-06-09 |
| CVE-2026-44662 | rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-padding | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2025-14575 | Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2025-14819 | OpenSSL partial chain store policy bypass | MEDIUM | 5.3 | 53%ile | Microsoft | 2026-01-13 |
| CVE-2025-9230 | Out-of-bounds read & write in RFC 3211 KEK Unwrap | HIGH | 7.5 | 74%ile | Microsoft | 2025-09-09 |
| CVE-2025-9232 | Out-of-bounds read in HTTP client no_proxy handling | MEDIUM | 5.9 | 80%ile | Microsoft | 2025-09-09 |
| CVE-2025-60018 | Glib-networking: out of bound reads on glib-networking through tls/openssl/gtlscertificate-openssl.c via "g_tls_certific | MEDIUM | 4.8 | 24%ile | Microsoft | 2025-09-09 |
| CVE-2025-60019 | Glib-networking: uninitialized memory dereferences on glib-networking through glib-networking/tls/openssl/gtlsbio.c via | LOW | 3.7 | 29%ile | Microsoft | 2025-09-09 |