Ultravnc
Vendor:
First CVE: Mar 5, 2019 · Active for 7 years
37
Total CVEs
More Total CVEs than 98% of tracked products
12.3
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ultravnc over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 5, 2019
7 years ago
Most Recent CVE
Jul 1, 2026
27 days ago
CVE Severity & Scoring
Ultravnc37 CVEs
14%
38%
46%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (10.8%)
Network33 (89.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (89.2%)
High4 (10.8%)
Unknown0 (0.0%)
User Interaction
None34 (91.9%)
Unknown0 (0.0%)
Required3 (8.1%)
Privileges Required
Low4 (10.8%)
High1 (2.7%)
None32 (86.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-7840CRITICAL UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The functions wi_senderr() and wi_replyhdr() in repeater/webgui/webu | Jul 1, 2026 | 9.8 | 44 | NO | NO |
CVE-2026-7838HIGH UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failure-response parsing path. In vncviewer/ClientConnection.cpp, | Jul 1, 2026 | 8.8 | 40 | NO | NO |
CVE-2026-7839CRITICAL UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, when settings2.txt is absent on f | Jul 1, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-7831HIGH UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In vncviewer/ClientConnection.cpp, when the server-supplied name | Jul 1, 2026 | 7.6 | 34 | NO | NO |
CVE-2019-8274CRITICAL UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer offer handler, which can potentially in result code execution. This attack a | Mar 8, 2019 | 9.8 | 33 | NO | NO |
CVE-2019-8273CRITICAL UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result in code execution. This attack | Mar 8, 2019 | 9.8 | 33 | NO | NO |
CVE-2026-7830HIGH UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAuth). In rfb/dh.cpp the Diffie-Hellman key exchange is perform | Jul 1, 2026 | 7.4 | 32 | NO | NO |
CVE-2026-7829HIGH UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. In repeater/webgui/settings.c:225-272, after strncpy_s copies a | Jul 1, 2026 | 7.2 | 32 | NO | NO |
CVE-2019-8264CRITICAL UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially result in code execution. This attack appears to be exploit | Mar 8, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-8260CRITICAL UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused by multiplication overflow. This attack appears to be exploitable via network c | Mar 5, 2019 | 9.8 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (37 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (37 CVEs).
Media Mentions
Signals from CVEs in this product scope (37 CVEs).
Top CNAs Publishing CVEs For Ultravnc
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.6.4.0 | 1 | 7.0 | 0.2% | 0 | 0 |