Leap
Vendor:
First CVE: Aug 31, 2012 · Active for 13 years
1,934
Total CVEs
More Total CVEs than 100% of tracked products
148.8
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
1.0%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Leap over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2012
13 years ago
Most Recent CVE
Apr 22, 2026
93 days ago
CVE Severity & Scoring
Leap1,934 CVEs
42%
43%
10%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local493 (25.5%)
Network1,307 (67.6%)
Unknown72 (3.7%)
Physical31 (1.6%)
Adjacent Network31 (1.6%)
Attack Complexity
Low1,594 (82.4%)
High268 (13.9%)
Unknown72 (3.7%)
User Interaction
None1,195 (61.8%)
Unknown72 (3.7%)
Required667 (34.5%)
Privileges Required
Low376 (19.4%)
High136 (7.0%)
None1,350 (69.8%)
Unknown72 (3.7%)
Top CVEs
Signals from CVEs in this product scope (1934 CVEs).
1,934 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31431HIGH In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the c | Apr 22, 2026 | 7.8 | 99 | YES | YES |
CVE-2020-1472CRITICAL An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc | Aug 17, 2020 | 10.0 | 99 | YES | YES |
CVE-2020-1938CRITICAL When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e | Feb 24, 2020 | 9.8 | 99 | YES | YES |
CVE-2019-5418HIGH There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrar | Mar 27, 2019 | 7.5 | 99 | YES | YES |
CVE-2020-16846CRITICAL An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection. | Nov 6, 2020 | 9.8 | 98 | YES | YES |
CVE-2020-11651CRITICAL An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a re | Apr 30, 2020 | 9.8 | 98 | YES | YES |
CVE-2016-3714HIGH The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to exec | May 5, 2016 | 8.4 | 98 | YES | YES |
CVE-2016-0752HIGH Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote | Feb 16, 2016 | 7.5 | 97 | YES | YES |
CVE-2025-32463HIGH Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. | Jun 30, 2025 | 7.8 | 96 | YES | YES |
CVE-2020-12641CRITICAL rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_ | May 4, 2020 | 9.8 | 96 | YES | YES |
Exploit Exposure
Signals from CVEs in this product scope (1934 CVEs).
CISA KEV
19 CVEs
1.0% of CVEs· 96th percentile
Metasploit
16 CVEs
0.8% of CVEs· 96th percentile
Nuclei
13 CVEs
0.7% of CVEs· 96th percentile
ExploitDB
44 CVEs
2.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (1934 CVEs).
Media Mentions
Signals from CVEs in this product scope (1934 CVEs).
Top CNAs Publishing CVEs For Leap
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 42.3 | 209 | 7.4 | 7.3% | 1 | 15 |
| 42.2 | 87 | 6.8 | 6.0% | 0 | 6 |
| 42.1 | 433 | 7.1 | 6.9% | 7 | 14 |
| 15.6 | 2 | 7.8 | 72.3% | 2 | 2 |
| 15.5 | 2 | 7.8 | 48.3% | 1 | 1 |
| 15.4 | 3 | 6.7 | 32.2% | 1 | 1 |
| 15.3 | 4 | 5.8 | 24.7% | 1 | 1 |
| 15.2 | 375 | 6.8 | 5.0% | 3 | 9 |
| 15.1 | 1,156 | 6.9 | 5.1% | 8 | 23 |
| 15.0 | 508 | 7.1 | 5.5% | 2 | 15 |