Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Znc

First CVE: Mar 3, 2009Active for: 17 yearsTotal CVEs: 16
19.5
VTI Score
Low

Znc is a modestly represented IRC bouncer and proxy application that maintains persistent connections to IRC networks on behalf of users, occupying a specialized niche in chat infrastructure despite its concentrated product footprint. The vulnerability profile centers on input-handling and access-control weaknesses—improper input validation, path traversal, NULL-pointer dereferences, and code-injection conditions—that recur across the core application and its containerized distributions, reflecting the parsing demands of IRC protocol handling and the sensitivity of a service that mediates authentication and message flow. Defenders should treat Znc instances as security-sensitive components, particularly when exposed to untrusted networks or run with elevated privileges; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 11% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Znc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 3, 2009
17 years ago
Most Recent CVE
Dec 8, 2020
2,054 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-29577CRITICAL
The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image
Dec 8, 20209.829NONO
CVE-2019-12816HIGH
Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module with a crafted name.
Jun 15, 20198.829NONO
CVE-2010-2488HIGH
NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connections.
Nov 12, 20197.525NONO
CVE-2020-13775MEDIUM
ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there is no network.
Jun 2, 20206.524NONO
CVE-2018-14055MEDIUM
ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inject rogue values into znc.conf.
Jul 15, 20186.522NONO
CVE-2018-14056MEDIUM
ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.
Jul 15, 20185.320NONO
CVE-2009-2658HIGH
Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.
Aug 4, 20097.520NONO
CVE-2012-0033MEDIUM
The CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in the bouncedcc module in ZNC 0.200 and 0.202 allows remote attackers to cause a denial of service (crash) via a crafted DC
Apr 8, 20145.019NONO
CVE-2010-2934MEDIUM
Multiple unspecified vulnerabilities in ZNC 0.092 allow remote attackers to cause a denial of service (exception and daemon crash) via unknown vectors related to "unsafe substr() c
Aug 17, 20105.019NONO
CVE-2010-2812MEDIUM
Client.cpp in ZNC 0.092 allows remote attackers to cause a denial of service (exception and daemon crash) via a PING command that lacks an argument.
Aug 17, 20105.019NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
69%
19%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (43.8%)
Unknown9 (56.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (43.8%)
High0 (0.0%)
Unknown9 (56.3%)
User Interaction
None7 (43.8%)
Unknown9 (56.3%)
Required0 (0.0%)
Privileges Required
Low4 (25.0%)
High0 (0.0%)
None3 (18.8%)
Unknown9 (56.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Znc.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Znc — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Znc's Products

View all 2 CNAs →

Top CWEs