Open-information-security-foundation
24 CVEs tracked since 2024. Since Feb 2024, none of them reached CISA KEV.
Open-information-security-foundation CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2024-02 | 5 | 0 |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | 5 | 0 |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | 7 | 0 |
| 2025-12 | null or fewer | |
| 2026-01 | 7 | 0 |
Products
The products that kept showing up in Open-information-security-foundation's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Open-information-security-foundation.
- CVE-2026-31937Suricata dcerpc: quadratic complexity in dcerpc buffering7.5
- CVE-2026-31935Suricata http2: unbounded resource consumption7.5
- CVE-2026-31934Suricata smtp/mine: quadratic complexity in extracting urls7.5
- CVE-2026-31933Suricata stream: quadratic complexity in stream inspection7.5
- CVE-2026-31932Suricata krb5: quadratic complexity in krb5 buffering7.5
- CVE-2026-31931Suricata tls: null dereference in tls.alpn rule keyword7.5
- CVE-2026-22264Suricata detect/alert: heap-use-after-free on alert queue expansion7.4
- CVE-2026-22263Suricata http1: quadratic complexity in headers parsing over multiple packets5.3
- CVE-2026-22262Suricata datasets: stack overflow when saving a set5.9
- CVE-2026-22261Suricata eve/alert: http1 xff handling can lead to denial of service3.7
- CVE-2026-22260Suricata http1: infinite recursion in decompression7.5
- CVE-2026-22259Suricata dnp3: unbounded transaction growth7.5
- CVE-2026-22258Suricata DCERPC: unbounded fragment buffering leads to memory exhaustion7.5
- CVE-2025-64344Suricata is vulnerable to a stack overflow from unbounded stack allocation in LuaPushStringBuffer7.5
- CVE-2025-64330Suricata is vulnerable to a heap buffer overflow on verdict7.5
The record
- Peak rank
- #111 in Nov 2025
- Busiest month shown
- Nov 2025, 7 CVEs
- Months with a KEV entry
- 0 since Feb 2024
- Monthly snapshots
- 4 since 2024