Tor
Vendor:
First CVE: Jun 28, 2005 · Active for 21 years
103
Total CVEs
More Total CVEs than 77% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 39% of tracked products
1.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 28, 2005
21 years ago
Most Recent CVE
May 7, 2026
78 days ago
CVE Severity & Scoring
Tor103 CVEs
61%
34%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.0%)
Network38 (36.9%)
Unknown64 (62.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (35.0%)
High3 (2.9%)
Unknown64 (62.1%)
User Interaction
None38 (36.9%)
Unknown64 (62.1%)
Required1 (1.0%)
Privileges Required
Low1 (1.0%)
High0 (0.0%)
None38 (36.9%)
Unknown64 (62.1%)
Top CVEs
Signals from CVEs in this product scope (103 CVEs).
103 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9079HIGH A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users | Jun 11, 2018 | 7.5 | 97 | YES | YES |
CVE-2018-0491HIGH A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a | Mar 5, 2018 | 7.5 | 42 | NO | YES |
CVE-2026-44597CRITICAL Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011. | May 7, 2026 | 9.1 | 34 | NO | NO |
CVE-2010-1676HIGH Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrar | Dec 22, 2010 | 10.0 | 33 | NO | NO |
CVE-2026-44603CRITICAL Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007. | May 7, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-44602HIGH Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006. | May 7, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-44601HIGH Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009. | May 7, 2026 | 7.5 | 28 | NO | NO |
CVE-2020-10592HIGH Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002. | Mar 23, 2020 | 7.5 | 26 | NO | NO |
CVE-2019-8955HIGH In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memor | Feb 21, 2019 | 7.5 | 26 | NO | NO |
CVE-2017-8823HIGH In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 d | Dec 3, 2017 | 8.1 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (103 CVEs).
CISA KEV
1 CVE
1.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
2.9% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (103 CVEs).
Media Mentions
Signals from CVEs in this product scope (103 CVEs).
Top CNAs Publishing CVEs For Tor
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.7 | 1 | 5.5 | 0.4% | 0 | 0 |
| 0.4.4.3 | 2 | 6.4 | 1.9% | 0 | 0 |
| 0.4.4.2 | 2 | 6.4 | 1.9% | 0 | 0 |
| 0.4.4.1 | 3 | 6.8 | 1.7% | 0 | 0 |
| 0.4.4.0 | 3 | 6.8 | 1.7% | 0 | 0 |
| 0.4.0.1 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.5.7 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.5.6 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.5.5 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.5.4 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.5.3 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.5.2 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.5.1 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.5.0 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.4.7 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.4.6 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.4.5 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.4.4 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.4.3 | 1 | 7.5 | 4.6% | 0 | 0 |
| 0.3.4.2 | 1 | 7.5 | 4.6% | 0 | 0 |