Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Serenityos

First CVE: Dec 31, 2019Active for: 7 yearsTotal CVEs: 8

SerenityOS is a hobby operating system developed as an educational project, with its vulnerability footprint concentrated in a single product spanning kernel, userspace utilities, and application frameworks. The recurring weaknesses—classic buffer overflows, path traversal, memory-boundary violations, integer overflows, and out-of-bounds writes—reflect the memory-safety challenges inherent to a from-scratch OS implementation in C++, and vulnerabilities affecting the project skew strongly toward critical severity. Defenders tracking this vendor should recognize its niche deployment context; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Serenityos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2019
6 years ago
Most Recent CVE
Mar 1, 2023
1,241 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-31272CRITICAL
SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalati
Jun 18, 20219.831NONO
CVE-2021-4327CRITICAL
A vulnerability was found in SerenityOS. It has been rated as critical. Affected by this issue is the function initialize_typed_array_from_array_buffer in the library Userland/Libr
Mar 1, 20239.829NONO
CVE-2021-30045CRITICAL
SerenityOS 2021-03-27 contains a buffer overflow vulnerability in the EndOfCentralDirectory::read() function.
Apr 6, 20219.128NONO
CVE-2021-33185HIGH
SerenityOS contains a buffer overflow in the set_range test in TestBitmap which could allow attackers to obtain sensitive information.
Jun 18, 20217.525NONO
CVE-2021-28874HIGH
SerenityOS fixed as of c9f25bca048443e317f1994ba9b106f2386688c3 contains a buffer overflow vulnerability in LibTextCode through opening a crafted file.
Apr 6, 20217.825NONO
CVE-2019-20172HIGH
Kernel/VM/MemoryManager.cpp in SerenityOS before 2019-12-30 does not reject syscalls with pointers into the kernel-only virtual address space, which allows local users to gain priv
Dec 31, 20197.825NONO
CVE-2021-33186HIGH
SerenityOS in test-crypto.cpp contains a stack buffer overflow which could allow attackers to obtain sensitive information.
Jun 18, 20217.524NONO
CVE-2021-27343HIGH
SerenityOS Unspecified is affected by: Buffer Overflow. The impact is: obtain sensitive information (context-dependent). The component is: /Userland/Libraries/LibCrypto/ASN1/DER.h
Apr 6, 20217.524NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
63%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local2 (25.0%)
Network6 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None7 (87.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Serenityos.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Serenityos — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Serenityos's Products

View all 2 CNAs →

Top CWEs