Vulnerability index

Browse CVEs

71 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-13379 The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service cras… Openvpn 2.7.5+ Fix from $2,3002026-07-30 HIGH 8.1 CVE-2026-12996 A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of serv… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 8.1 CVE-2026-13117 An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 8.1 CVE-2026-12932 A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-11771 OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2025-3110 OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP reque… Openvpn Access Server after 3.1.0 Fix from $1,9502026-07-08 MEDIUM 5.3 CVE-2026-13122 OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication… Openvpn 2.6.21 / 2.7.5+ Fix from $1,6002026-07-06 HIGH 7.5 CVE-2026-13698 A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-cry… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-06 MEDIUM 6.5 CVE-2026-11604 An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated pee… Openvpn after 2.8.3 Fix from $1,6002026-06-10 HIGH 7.4 CVE-2026-40215 A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak hea… Openvpn 2.6.20 / 2.7.2+ Fix from $1,9502026-06-08 MEDIUM 6.5 CVE-2026-35058 Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authentic… Openvpn 2.6.20 / 2.7.2+ Fix from $1,6002026-06-08 HIGH 7.8 CVE-2026-9560 Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with eleva… Connect 3.8.2+ Fix from $1,9502026-05-26 HIGH 7.5 CVE-2025-13086 Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a sessio… Openvpn 2.6.16+ Fix from $1,9502025-12-03 MEDIUM 5.5 CVE-2025-13751 Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to conn… Openvpn 2.6.17+ Fix from $1,6002025-12-03 CRITICAL 9.1 CVE-2025-12106 Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses Openvpn Mitigation only Fix from $2,3002025-12-01 MEDIUM 5.5 CVE-2025-50054 Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large contr… Ovpn Dco Win after 2.5.8 Fix from $1,6002025-06-20 MEDIUM 6.2 CVE-2025-3908 The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary di… Openvpn3linux after 24 Fix from $1,6002025-05-19 HIGH 8.8 CVE-2024-4877 OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component … Openvpn 2.6.11+ Fix from $1,9502025-04-03 HIGH 7.5 CVE-2025-2704 OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and repla… Openvpn after 2.6.13 Fix from $1,9502025-04-02 MEDIUM 5.3 CVE-2024-13454 Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when created u… Easy Rsa after 3.1.7 Fix from $1,6002025-01-20 HIGH 7.5 CVE-2024-8474 OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an … Connect 3.5.0+ Fix from $1,9502025-01-06 CRITICAL 9.1 CVE-2024-5594 OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary d… Openvpn 2.6.11+ Fix from $2,3002025-01-06 CRITICAL 9.8 CVE-2024-1305EPSS 15% tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overf… Tap Windows6 after 9.26.0 Fix from $2,3002024-07-08 CRITICAL 9.8 CVE-2024-27903EPSS 9% OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in … Openvpn 2.5.10 / 2.6.10+ Fix from $2,3002024-07-08 HIGH 7.8 CVE-2024-27459EPSS 8% The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary … Openvpn 2.5.10 / 2.6.10+ Fix from $1,9502024-07-08 HIGH 7.5 CVE-2024-24974EPSS 10% The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to inter… Openvpn 2.5.10 / 2.6.10+ Fix from $1,9502024-07-08 MEDIUM 6.5 CVE-2023-6247 The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application c… Openvpn 3 3.8.4+ Fix from $1,6002024-02-29 HIGH 8.4 CVE-2023-7235 The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries w… Openvpn Gui 2.6.9+ Fix from $1,9502024-02-21 HIGH 7.8 CVE-2023-7245 The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute a… Connect 3.4.4 / 3.4.8+ Fix from $1,9502024-02-20 HIGH 7.8 CVE-2023-7224 OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARI… Connect after 3.4.6 Fix from $1,9502024-01-08