Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ethereum

First CVE: Jan 19, 2018Active for: 9 yearsTotal CVEs: 39
39.9
VTI Score
Medium

Ethereum's vulnerability profile centers on a narrow but prominent set of blockchain client implementations, including Go Ethereum and C++ Ethereum variants, that serve as critical infrastructure for consensus participation and network synchronization. Vulnerabilities affecting these clients span weakness classes rooted in authorization logic, input validation at the protocol and transaction-processing boundary, arithmetic correctness in state calculations, and resource-consumption controls—exposures inherent to decentralized consensus systems where malformed or malicious inputs must be validated without trust. The moderate tendency of these disclosures toward serious outcomes reflects the high-value and availability-critical role these clients play in the blockchain ecosystem; defenders operating validators or full nodes should treat client advisories as urgent and prioritize rapid patching to maintain consensus integrity and prevent state divergence. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
39
Total CVEs
More Total CVEs than 98% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ethereum over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 19, 2018
8 years ago
Most Recent CVE
Feb 19, 2026
155 days ago

Products(9 total)

Top CVEs

Signals from CVEs in this vendor scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-14451CRITICAL
An exploitable out-of-bounds read vulnerability exists in libevm (Ethereum Virtual Machine) of CPP-Ethereum. A specially crafted smart contract code can cause an out-of-bounds read
Dec 2, 202010.033NONO
CVE-2018-15890CRITICAL
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and
Jun 20, 20199.830NONO
CVE-2018-18920HIGH
Py-EVM v0.2.0-alpha.33 allows attackers to make a vm.execute_bytecode call that triggers computation._stack.values with '"stack": [100, 100, 0]' where b'\x' was expected, resulting
Nov 12, 20188.828NONO
CVE-2026-26314HIGH
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash using a specially
Feb 19, 20267.527NONO
CVE-2022-23328HIGH
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of
Mar 4, 20227.527NONO
CVE-2022-23327HIGH
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pendin
Mar 4, 20227.527NONO
CVE-2026-22862HIGH
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vu
Jan 13, 20267.526NONO
CVE-2017-14457HIGH
An exploitable information leak/denial of service vulnerability exists in the libevm (Ethereum Virtual Machine) `create2` opcode handler of CPP-Ethereum. A specially crafted smart
Jan 19, 20188.226NONO
CVE-2017-12118HIGH
An exploitable improper authorization vulnerability exists in miner_stop API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). An attacker can send JSON
Jan 19, 20188.126NONO
CVE-2017-12113HIGH
An exploitable improper authorization vulnerability exists in admin_nodeInfo API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can ca
Jan 19, 20188.126NONO
View all 39 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products39 CVEs
23%
72%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (5.1%)
Network37 (94.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (74.4%)
High10 (25.6%)
Unknown0 (0.0%)
User Interaction
None36 (92.3%)
Unknown0 (0.0%)
Required3 (7.7%)
Privileges Required
Low5 (12.8%)
High0 (0.0%)
None34 (87.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (39 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ethereum.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ethereum — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ethereum's Products

View all 4 CNAs →

Top CWEs