Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.1
CVE-2026-13379
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service cras…
Openvpn
2.7.5+
HIGH 8.1
CVE-2026-12996
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of serv…
Openvpn
2.6.21 / 2.7.5+
HIGH 8.1
CVE-2026-13117
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during…
Openvpn
2.6.21 / 2.7.5+
HIGH 8.1
CVE-2026-12932
A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause…
Openvpn
2.6.21 / 2.7.5+
HIGH 7.5
CVE-2026-11771
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to…
Openvpn
2.6.21 / 2.7.5+
HIGH 7.5
CVE-2025-3110
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP reque…
Openvpn Access Server
after 3.1.0
MEDIUM 5.3
CVE-2026-13122
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication…
Openvpn
2.6.21 / 2.7.5+
HIGH 7.5
CVE-2026-13698
A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-cry…
Openvpn
2.6.21 / 2.7.5+
MEDIUM 6.5
CVE-2026-11604
An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated pee…
Openvpn
after 2.8.3
HIGH 7.4
CVE-2026-40215
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak hea…
Openvpn
2.6.20 / 2.7.2+
MEDIUM 6.5
CVE-2026-35058
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authentic…
Openvpn
2.6.20 / 2.7.2+
HIGH 7.8
CVE-2026-9560
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with eleva…
Connect
3.8.2+
HIGH 7.5
CVE-2025-13086
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a sessio…
Openvpn
2.6.16+
MEDIUM 5.5
CVE-2025-13751
Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to conn…
Openvpn
2.6.17+
CRITICAL 9.1
CVE-2025-12106
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
Openvpn
Mitigation only
MEDIUM 5.5
CVE-2025-50054
Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large contr…
Ovpn Dco Win
after 2.5.8
MEDIUM 6.2
CVE-2025-3908
The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary di…
Openvpn3linux
after 24
HIGH 8.8
CVE-2024-4877
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component …
Openvpn
2.6.11+
HIGH 7.5
CVE-2025-2704
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and repla…
Openvpn
after 2.6.13
MEDIUM 5.3
CVE-2024-13454
Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when created u…
Easy Rsa
after 3.1.7
HIGH 7.5
CVE-2024-8474
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an …
Connect
3.5.0+
CRITICAL 9.1
CVE-2024-5594
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary d…
Openvpn
2.6.11+
CRITICAL 9.8
CVE-2024-1305EPSS 15%
tap-windows6 driver version 9.26 and earlier does not properly
check the size data of incomming write operations which an attacker can
use to overf…
Tap Windows6
after 9.26.0
CRITICAL 9.8
CVE-2024-27903EPSS 9%
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in …
Openvpn
2.5.10 / 2.6.10+
HIGH 7.8
CVE-2024-27459EPSS 8%
The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary …
Openvpn
2.5.10 / 2.6.10+
HIGH 7.5
CVE-2024-24974EPSS 10%
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to inter…
Openvpn
2.5.10 / 2.6.10+
MEDIUM 6.5
CVE-2023-6247
The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application c…
Openvpn 3
3.8.4+
HIGH 8.4
CVE-2023-7235
The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries w…
Openvpn Gui
2.6.9+
HIGH 7.8
CVE-2023-7245
The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute a…
Connect
3.4.4 / 3.4.8+
HIGH 7.8
CVE-2023-7224
OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARI…
Connect
after 3.4.6