Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

OpenSSL Software Foundation

First CVE: Mar 22, 1999Active for: 27 yearsTotal CVEs: 306
63.8
VTI Score
TOP TARGET

The OpenSSL Software Foundation maintains a cryptographic library that, despite a minimal product roster, occupies a critical position in the global software supply chain and is embedded across an enormous range of servers, appliances, and applications. The vendor's exposure is heavily represented in the vulnerability landscape precisely because a single flaw can propagate to every downstream product that links the library, amplifying the practical impact of each disclosure. Vulnerabilities skew toward serious outcomes, particularly within the core OpenSSL and FIPS Object Module products, and recur through weakness classes including NULL-pointer dereferences, certificate validation bypasses, memory-buffer violations, and information-exposure conditions that reflect the parsing complexity and cryptographic-state management inherent to a TLS and general-purpose crypto implementation. Many OpenSSL vulnerabilities acquire public exploit tooling, underscoring the appeal of the library as a target for attackers seeking to compromise downstream systems at scale. Defenders should inventory and prioritize remediation of products that bundle this library rather than tracking the library alone, as exposure depends heavily on which downstream vendors and deployment contexts have integrated and updated it; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
306
Total CVEs
More Total CVEs than 100% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by OpenSSL Software Foundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 22, 1999
27 years ago
Most Recent CVE
Jun 9, 2026
45 days ago

Self-Reporting Analysis

Of all the CVEs published by OpenSSL Software Foundation as a CNA, 100.0% affect products that OpenSSL Software Foundation develops as a vendor.

100.0%
Self-reported: 119 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by OpenSSL Software Foundation, 38.9% are self-published by OpenSSL Software Foundation as a CNA.

38.9%
61.1%
Self-published: 119 (38.9%)
Other CNAs: 187 (61.1%)

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (306 CVEs).

306 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-0160HIGH
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform
Apr 7, 20147.599YESYES
CVE-2009-3555CRITICAL
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier,
Nov 9, 20099.885NOYES
CVE-2014-0224HIGH
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to
Jun 5, 20147.483NOYES
CVE-2002-0656HIGH
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a lar
Aug 12, 20027.581NOYES
CVE-2014-0195MEDIUM
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS Clie
Jun 5, 20146.880NOYES
CVE-2021-3711CRITICAL
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim
Aug 24, 20219.879NONO
CVE-2016-2107MEDIUM
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obta
May 5, 20165.979NOYES
CVE-2014-3566LOW
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear
Oct 15, 20143.478NOYES
CVE-2016-2183HIGH
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which mak
Sep 1, 20167.577NONO
CVE-2009-1386MEDIUM
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occur
Jun 4, 20095.077NOYES
View all 306 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products306 CVEs
58%
32%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local16 (5.2%)
Network158 (51.6%)
Unknown131 (42.8%)
Physical1 (0.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low118 (38.6%)
High57 (18.6%)
Unknown131 (42.8%)
User Interaction
None166 (54.2%)
Unknown131 (42.8%)
Required9 (2.9%)
Privileges Required
Low16 (5.2%)
High1 (0.3%)
None158 (51.6%)
Unknown131 (42.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (306 CVEs).

CISA KEV
1 CVE
0.3% of CVEs· 99th percentile
Metasploit
10 CVEs
3.3% of CVEs· 98th percentile
Nuclei
1 CVE
0.3% of CVEs· 95th percentile
ExploitDB
19 CVEs
6.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by OpenSSL Software Foundation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by OpenSSL Software Foundation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For OpenSSL Software Foundation's Products

View all 5 CNAs →

Top CWEs