Vyper
Vendor:
First CVE: Oct 5, 2021 · Active for 4 years
38
Total CVEs
More Total CVEs than 97% of tracked products
7.6
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vyper over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2021
4 years ago
Most Recent CVE
Feb 21, 2025
520 days ago
CVE Severity & Scoring
Vyper38 CVEs
47%
34%
18%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network38 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (94.7%)
High2 (5.3%)
Unknown0 (0.0%)
User Interaction
None38 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (5.3%)
High0 (0.0%)
None36 (94.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24788CRITICAL Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Versions of vyper prior to 0.3.2 suffer from a potential buffer overrun. Importing a function from a J | Apr 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-24561CRITICAL Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account for the ability for start | Feb 1, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-24563CRITICAL Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, while they are defined for unsigned integers only. The typech | Feb 7, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-31146CRITICAL Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, during codegen, the length word of a dynarray is written before the data, whic | May 11, 2023 | 9.1 | 27 | NO | NO |
CVE-2021-41121HIGH Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions when performing a function call inside a literal struct, there is a memory corruption issue that occur | Oct 6, 2021 | 8.8 | 27 | NO | NO |
CVE-2025-27105CRITICAL vyper is a Pythonic Smart Contract Language for the EVM. Vyper handles AugAssign statements by first caching the target location to avoid double evaluation. However, in the case wh | Feb 21, 2025 | 9.1 | 26 | NO | NO |
CVE-2024-22419CRITICAL Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. The `concat` built-in can write over the bounds of the memory buffer that was allocated for it and thu | Jan 18, 2024 | 9.8 | 26 | NO | NO |
CVE-2022-24787HIGH Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. In version 0.3.1 and prior, bytestrings can have dirty bytes in them, resulting in the word-for-word c | Apr 4, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-32058HIGH Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, due to missing overflow check for loop variables, by assigning the iterator of | May 11, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-30837HIGH Vyper is a pythonic smart contract language for the EVM. The storage allocator does not guard against allocation overflows in versions prior to 0.3.8. An attacker can overwrite the | May 8, 2023 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (38 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (38 CVEs).
Media Mentions
Signals from CVEs in this product scope (38 CVEs).
Top CNAs Publishing CVEs For Vyper
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.4.0 | 1 | 5.3 | 0.8% | 0 | 0 |
| 0.3.0 | 1 | 5.9 | 0.7% | 0 | 0 |
| 0.2.16 | 1 | 5.9 | 0.7% | 0 | 0 |
| 0.2.15 | 1 | 5.9 | 0.7% | 0 | 0 |