Leap

Vendor:

First CVE: Aug 31, 2012 · Active for 13 years

1,934
Total CVEs
More Total CVEs than 100% of tracked products
148.8
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
1.0%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Leap over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2012
13 years ago
Most Recent CVE
Apr 22, 2026
93 days ago

CVE Severity & Scoring

Leap1,934 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local493 (25.5%)
Network1,307 (67.6%)
Unknown72 (3.7%)
Physical31 (1.6%)
Adjacent Network31 (1.6%)
Attack Complexity
Low1,594 (82.4%)
High268 (13.9%)
Unknown72 (3.7%)
User Interaction
None1,195 (61.8%)
Unknown72 (3.7%)
Required667 (34.5%)
Privileges Required
Low376 (19.4%)
High136 (7.0%)
None1,350 (69.8%)
Unknown72 (3.7%)

Top CVEs

Signals from CVEs in this product scope (1934 CVEs).

1,934 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c
Apr 22, 20267.899YESYES
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc
Aug 17, 202010.099YESYES
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrar
Mar 27, 20197.599YESYES
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
Nov 6, 20209.898YESYES
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a re
Apr 30, 20209.898YESYES
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to exec
May 5, 20168.498YESYES
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote
Feb 16, 20167.597YESYES
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
Jun 30, 20257.896YESYES
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_
May 4, 20209.896YESYES

Exploit Exposure

Signals from CVEs in this product scope (1934 CVEs).

CISA KEV
19 CVEs
1.0% of CVEs· 96th percentile
Metasploit
16 CVEs
0.8% of CVEs· 96th percentile
Nuclei
13 CVEs
0.7% of CVEs· 96th percentile
ExploitDB
44 CVEs
2.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (1934 CVEs).

Media Mentions

Signals from CVEs in this product scope (1934 CVEs).

Top CNAs Publishing CVEs For Leap

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
42.32097.47.3%115
42.2876.86.0%06
42.14337.16.9%714
15.627.872.3%22
15.527.848.3%11
15.436.732.2%11
15.345.824.7%11
15.23756.85.0%39
15.11,1566.95.1%823
15.05087.15.5%215