Openlinksw maintains Virtuoso, a widely embedded data management and semantic-web platform that integrates database, middleware, and linked-data functionality into enterprise and analytics environments. The vendor's vulnerability footprint, though concentrated in a single product, carries outsized relevance because Virtuoso's role as middleware and data-integration layer means individual flaws can propagate across dependent applications and workflows. The recurring weakness classes center on input-handling and resource-management issues—particularly SQL injection, resource exhaustion, and improper cleanup—that are characteristic of complex, integration-heavy database platforms exposed to untrusted or high-volume query input. Defenders should monitor Virtuoso deployments in data pipelines and business-intelligence layers and treat input validation and resource limits as focal points for hardening; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openlinksw over time
Signals from CVEs in this vendor scope (63 CVEs).
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31631HIGH An issue in the sqlo_preds_contradiction component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | May 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-31630HIGH An issue in the sqlo_query_spec component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | May 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-31629HIGH An issue in the sqlo_union_scope component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | May 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-31628HIGH An issue in the stricmp component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | May 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-31625HIGH An issue in the psiginfo component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | May 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-31624HIGH An issue in the sinv_check_exp component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | May 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-31623HIGH An issue in the mp_box_copy component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | May 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-31622HIGH An issue in the sqlc_make_policy_trig component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | May 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-31621HIGH An issue in the kc_var_col component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | May 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-31619HIGH An issue in the sch_name_to_object component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | May 15, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (63 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openlinksw.
Media articles that mention a CVE ID that affects a product developed by Openlinksw — matched by CVE ID, not by vendor name.