CVE security advisories and vulnerability history for OpenSSL.
OpenSSL has 319 published CVE records since 2000, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 45 have a known public exploit. The average CVSS base score across scored CVEs is 6.2.
This page aggregates every publicly disclosed vulnerability (CVE) affecting OpenSSL products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.
A quick read on OpenSSL's vulnerability posture, as a share of its 319 published CVEs.
across 319 scored CVEs
127 of 319 scored
1 of 319 CVEs
45 of 319 CVEs
300 of 319 CVEs
How the CVSS severity of OpenSSL's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of OpenSSL's CVEs is confirmed exploited in the wild.
Public exploits
45
45 of OpenSSL's CVEs have a known public exploit available.
The OpenSSL products with the most published CVEs. Follow any product to browse its versions and vulnerabilities.
The CWE weakness categories most often found in OpenSSL CVEs. Follow any weakness for its full explanation.
The CVE Numbering Authorities that publish OpenSSL CVE records.
How many OpenSSL CVEs were published each year.
The most recently disclosed vulnerabilities affecting OpenSSL.
Browse vulnerabilities for other tracked vendors.
Common questions about OpenSSL vulnerabilities.
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Monitor new OpenSSL vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.
Track new OpenSSL CVEs as they are disclosed and get AI-written analysis and remediation guidance.
Monitor OpenSSL CVEs