CVE security advisories and vulnerability history for tor by torproject.
41
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
4
Public exploits
With known exploit
4.8
Avg CVSS
2012–2026
Last updated
Overview
torproject tor has 41 published CVE records since 2012, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 4 have a known public exploit. The average CVSS base score across scored CVEs is 4.8.
This page aggregates every publicly disclosed vulnerability (CVE) affecting torproject tor, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of torproject tor's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical1
High0
Medium1
Low6
33 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of torproject tor's CVEs is confirmed exploited in the wild.
Public exploits
4
4 of torproject tor's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every torproject tor version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about torproject tor vulnerabilities.
How many CVEs does torproject tor have?
torproject tor has 41 published CVE records since 2012.
How many torproject tor CVEs are in CISA KEV?
Yes — 1 of torproject tor's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for torproject tor vulnerabilities?
Yes — 4 of torproject tor's CVEs have a known public exploit.
Which versions of torproject tor are affected?
449 distinct torproject tor versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in torproject tor CVEs?
torproject tor's CVEs most often map to these CWE weakness types: CWE-193 (Off-by-one Error), CWE-416 (Use After Free), CWE-476 (NULL Pointer Dereference), CWE-669 (Incorrect Resource Transfer Between Spheres).
How many critical torproject tor vulnerabilities are there?
torproject tor has 1 critical and 0 high-severity CVEs.
What is the average severity of torproject tor CVEs?
The average CVSS base score across torproject tor's scored CVEs is 4.8.