CVE Tools

SSH2

12 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for SSH2, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

SSH2 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
SSH2 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical18%
  • High542%
  • Medium650%

Latest CVEs

The 12 most recently published vulnerabilities affecting SSH2.

  1. CVE-2025-70034An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in mscdex ssh2 v1.17.0.7.5
  2. CVE-2023-48795The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (fr...5.9
  3. CVE-2020-26301Command injection in mscdex/ssh27.5
  4. CVE-2002-1715SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script t...7.2
  5. CVE-2002-1645Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL.10.0
  6. CVE-2002-1644SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the p...7.2
  7. CVE-2001-0364SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections.5.0
  8. CVE-1999-1159SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.4.6
  9. CVE-1999-1231ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows rem...5.0
  10. CVE-1999-1029SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without sho...7.5
  11. CVE-2000-0217The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.5.1
  12. CVE-1999-0398In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.4.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store