Pjsip
Vendor:
First CVE: Nov 17, 2017 · Active for 8 years
32
Total CVEs
More Total CVEs than 96% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pjsip over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2017
8 years ago
Most Recent CVE
May 7, 2026
79 days ago
CVE Severity & Scoring
Pjsip32 CVEs
13%
31%
56%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network32 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (90.6%)
High3 (9.4%)
Unknown0 (0.0%)
User Interaction
None31 (96.9%)
Unknown0 (0.0%)
Required1 (3.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None32 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23608CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions | Feb 22, 2022 | 9.8 | 33 | NO | NO |
CVE-2021-37706CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected | Dec 22, 2021 | 9.8 | 33 | NO | NO |
CVE-2021-43301CRITICAL Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a buffer overflow since it is copied to a fixed-size stack bu | Feb 16, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-31031CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions | Jun 9, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-43303CRITICAL Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an output buffer smaller than 128 c | Feb 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-43300CRITICAL Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buff | Feb 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-43299CRITICAL Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer | Feb 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-21723CRITICAL PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions | Jan 27, 2022 | 9.1 | 31 | NO | NO |
CVE-2017-16872CRITICAL An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cseq, ttl, port, etc.) all had the | Nov 17, 2017 | 9.8 | 31 | NO | NO |
CVE-2026-34235CRITICAL PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer | Mar 31, 2026 | 9.1 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (32 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (32 CVEs).
Media Mentions
Signals from CVEs in this product scope (32 CVEs).
Top CNAs Publishing CVEs For Pjsip
Top CWEs
Versions
No cataloged versions.