CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: OpenVPN Remove filter Clear all
CVE-2026-82325 MEDIUM

A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via craf…

CVSS 6.8 EPSS 0.14% Sep 7, 2026
CVE-2026-84732 HIGH

openvpn: OpenVPN: Remote Denial of Service via crafted ACK packets

CVSS 8.7 EPSS 0.54% Sep 7, 2026
CVE-2026-84256 HIGH

OpenVPN: OpenVPN: Arbitrary command execution via crafted certificate subject

CVSS 7.7 EPSS 0.38% Sep 7, 2026
CVE-2026-84226 HIGH

OpenVPN: OpenVPN: Arbitrary Code Execution via Binary Planting on Windows

CVSS 8.5 EPSS 0.14% Sep 7, 2026
CVE-2026-82312 LOW

openvpn: OpenVPN: Denial of service via NULL DACL on named IPC objects

CVSS 1.8 EPSS 0.10% Sep 7, 2026
CVE-2026-81830 MEDIUM

OpenVPN: OpenVPN: Security Bypass via incorrect file path validation

CVSS 5.6 EPSS 0.15% Sep 7, 2026
CVE-2026-81738 LOW

openvpn: OpenVPN: Out-of-bounds write via crafted DOMAIN-SEARCH entries

CVSS 2.3 EPSS 0.33% Sep 7, 2026
CVE-2026-78221 MEDIUM

OpenVPN: OpenVPN: Memory corruption and information disclosure vulnerability

CVSS 5.9 EPSS 0.12% Sep 7, 2026
CVE-2026-78043 MEDIUM

OpenVPN: OpenVPN: Privilege Escalation via Arbitrary Configuration File Loading

CVSS 5.6 EPSS 0.17% Sep 7, 2026
CVE-2026-63650 LOW

openvpn: mbedtls: OpenVPN: User misidentification via ignored X.509 identity field

CVSS 2.0 EPSS 0.36% Aug 14, 2026
CVE-2026-63649 MEDIUM

openvpn: OpenVPN: Privilege escalation via arbitrary configuration file loading

CVSS 4.1 EPSS 0.33% Aug 14, 2026
CVE-2026-12932 HIGH

openvpn: OpenVPN: Denial of Service due to memory leak in tls-crypt-v2 client key extraction

CVSS 7.1 EPSS 0.75% Jul 30, 2026
CVE-2026-12996 MEDIUM

OpenVPN: OpenVPN: Denial of Service or memory leak via crafted packets

CVSS 6.0 EPSS 0.81% Jul 30, 2026
CVE-2026-11771 HIGH

openvpn: OpenVPN: Denial of Service via crafted NTLM proxy response

CVSS 7.0 EPSS 0.68% Jul 30, 2026
CVE-2026-13117 MEDIUM

OpenVPN: OpenVPN: Denial of service or memory leakage via incomplete TLS guard

CVSS 6.0 EPSS 0.64% Jul 30, 2026
CVE-2026-13379 MEDIUM

OpenVPN: OpenVPN: Remote attackers can cause DNS state pollution or service crash via crafted search domain.

CVSS 5.1 EPSS 0.59% Jul 30, 2026
CVE-2025-3110 MEDIUM

OpenVPN Access Server: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers

CVSS 6.9 EPSS 0.45% Jul 8, 2026
CVE-2026-13122 MEDIUM

openvpn: From CVEorg collector

CVSS 5.9 EPSS 0.46% Jul 6, 2026
CVE-2026-13698 MEDIUM

openvpn: From CVEorg collector

CVSS 6.0 EPSS 0.55% Jul 6, 2026
CVE-2026-11604 MEDIUM

An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigg…

CVSS 5.6 EPSS 0.34% Jun 10, 2026
CVE-2026-40215 MEDIUM

openvpn: OpenVPN: Server crash or memory leak due to race condition and use-after-free

CVSS 6.1 EPSS 0.59% Jun 8, 2026
CVE-2026-35058 MEDIUM

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attac…

CVSS 6.9 EPSS 0.60% Jun 8, 2026
CVE-2026-9560 CRITICAL

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privil…

CVSS 9.4 EPSS 0.38% May 26, 2026
CVE-2026-2738 MEDIUM

Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packets to the remote peer when the AEAD tag…

CVSS 5.6 EPSS 0.13% Feb 19, 2026
CVE-2025-15497 LOW

Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of se…

CVSS 3.8 EPSS 0.36% Jan 30, 2026

Showing 1 to 25 CVEs · page 1 (more available)