Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openbsd

First CVE: Aug 24, 1997Active for: 29 yearsTotal CVEs: 357
65.4
VTI Score
TOP TARGET

OpenBSD's vulnerability footprint, concentrated in a small set of carefully maintained core products, carries outsized significance in the infrastructure landscape owing to the operating system's adoption in security-sensitive deployments and the widespread distribution of its derived components such as OpenSSH, LibreSSL, and OpenSMTPD. Despite a modest product count, the vendor's disclosures span a large volume of CVEs and frequently acquire public exploit code, reflecting both the scrutiny these widely trusted security tools attract and their role in critical network boundaries. Vulnerabilities recur through memory-safety and input-validation weakness classes, including buffer-boundary conditions, improper input validation, and information-disclosure flaws that are characteristic of low-level system software and cryptographic libraries. Defenders should monitor this vendor's advisories closely for patches affecting SSH, TLS, and mail infrastructure components, as updates often propagate rapidly through automated deployment pipelines; live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
357
Total CVEs
More Total CVEs than 100% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Openbsd over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 1997
28 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (357 CVEs).

357 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-7247CRITICAL
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP sessio
Jan 29, 20209.899YESYES
CVE-2024-6387HIGH
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth
Jul 1, 20248.189NOYES
CVE-2018-15473MEDIUM
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has be
Aug 17, 20185.386NOYES
CVE-2016-6210MEDIUM
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remo
Feb 13, 20175.984NOYES
CVE-2023-48795MEDIUM
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet
Dec 18, 20235.981NOYES
CVE-2003-0466CRITICAL
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 throug
Aug 27, 20039.881NOYES
CVE-2003-0190MEDIUM
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine va
May 12, 20035.078NOYES
CVE-2023-38408CRITICAL
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-con
Jul 20, 20239.877NONO
CVE-2023-25136MEDIUM
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unaut
Feb 3, 20236.571NONO
CVE-2007-5365HIGH
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote a
Oct 11, 20077.271NOYES
View all 357 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products357 CVEs
8%
46%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local46 (12.9%)
Network93 (26.1%)
Unknown214 (59.9%)
Physical0 (0.0%)
Adjacent Network4 (1.1%)
Attack Complexity
Low108 (30.3%)
High35 (9.8%)
Unknown214 (59.9%)
User Interaction
None125 (35.0%)
Unknown214 (59.9%)
Required18 (5.0%)
Privileges Required
Low47 (13.2%)
High2 (0.6%)
None94 (26.3%)
Unknown214 (59.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (357 CVEs).

CISA KEV
1 CVE
0.3% of CVEs· 99th percentile
Metasploit
7 CVEs
2.0% of CVEs· 97th percentile
Nuclei
2 CVEs
0.6% of CVEs· 95th percentile
ExploitDB
66 CVEs
18.5% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openbsd.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openbsd — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openbsd's Products

View all 11 CNAs →

Top CWEs