Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

P11 Kit Project

First CVE: Dec 16, 2020Active for: 6 yearsTotal CVEs: 8

P11 Kit Project maintains a focused cryptographic abstraction library that enables applications to access PKCS#11 hardware security modules and smart cards, positioning it as a critical intermediary in the security infrastructure of many Linux distributions and applications. The vulnerability surface is narrow in scope, centered on the library itself, though defenders should recognize that flaws here can propagate broadly across any product that depends on this library for HSM or certificate handling. Current exposure counts and exploitation activity are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
2.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by P11 Kit Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 16, 2020
5 years ago
Most Recent CVE
Jun 29, 2026
25 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-2100HIGH
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mech
Mar 26, 20267.534NONO
CVE-2026-13757MEDIUM
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive c
Jun 29, 20266.232NONO
CVE-2020-29363HIGH
An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the clien
Dec 16, 20207.525NONO
CVE-2020-29361HIGH
An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list comm
Dec 16, 20207.520NONO
CVE-2020-29362MEDIUM
An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the c
Dec 16, 20205.319NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
40%
60%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (20.0%)
Network4 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by P11 Kit Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by P11 Kit Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For P11 Kit Project's Products

View all 2 CNAs →

Top CWEs