Open-Xchange

First CVE: Apr 4, 2023Active for: 3 years
146
CVEs Published
More CVEs Published than 75% of tracked CNAs
36.5
Avg CVEs / Year
More Avg CVEs / Year than 80% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 16% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Open-Xchange as a CNA, 0.0% affect products that Open-Xchange develops as a vendor.

100.0%
Self-reported: 0Third-party: 146

Trends Over Time

The number and severity of CVEs published by Open-Xchange over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 4, 2023
3 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by Open-Xchange as a CNA, regardless of affected vendor or product.

146 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.
Jun 25, 20267.535NONO
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can
May 12, 20269.135NONO
Insufficient Validation of Names During AXFR
May 21, 20268.634NONO
Concurrency and locking defects in GSS-TSIG
May 21, 20267.533NONO
Insufficient Validation of Autoprimary SOA Queries
May 21, 20267.533NONO
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-
Mar 31, 20268.232NONO
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
Jul 23, 20267.530NONO
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still
May 12, 20267.530NONO
An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, lea
Apr 22, 20269.830NONO
An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in cust
Mar 31, 20267.530NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA146 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local6 (4.1%)
Network132 (90.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network8 (5.5%)
Attack Complexity
Low123 (84.2%)
High23 (15.8%)
Unknown0 (0.0%)
User Interaction
None116 (79.5%)
Unknown0 (0.0%)
Required30 (20.5%)
Privileges Required
Low44 (30.1%)
High4 (2.7%)
None98 (67.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (146 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Open-Xchange as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Open-Xchange as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs