Openvas is a modestly represented vulnerability-scanning platform whose disclosures concentrate in a narrow product line: the Openvas manager, scanner, and administrator components. The recurring weakness classes—spanning improper authentication and input validation, SQL injection, insecure file-access patterns, and unrestricted file uploads—reflect the application's role as a network-accessible service that ingests and processes user-supplied scanning configurations and result data. Defenders deploying this scanner should restrict network access to trusted administrators, keep the platform patched, and monitor for authentication and file-handling issues; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openvas over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-0018HIGH The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execute arbitrary commands via the (1) To or | Jan 28, 2011 | 9.0 | 45 | NO | YES |
CVE-2013-6765HIGH OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for v | May 19, 2014 | 7.5 | 38 | NO | YES |
CVE-2011-1597HIGH OpenVAS Manager v2.0.3 allows plugin remote code execution. | Feb 6, 2020 | 8.8 | 28 | NO | NO |
CVE-2012-5520HIGH The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute arbitrary commands via the (1) IP address or (2) port number | Nov 26, 2012 | 7.5 | 24 | NO | NO |
CVE-2011-3351HIGH openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker | Nov 25, 2019 | 7.1 | 23 | NO | NO |
CVE-2014-9220HIGH SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_sc | Dec 3, 2014 | 7.5 | 20 | NO | NO |
CVE-2013-6766HIGH OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execute OAP commands via a crafted OAP request | May 19, 2014 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openvas.
Media articles that mention a CVE ID that affects a product developed by Openvas — matched by CVE ID, not by vendor name.