OpenZeppelin records
22 published records for vendor openzeppelin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 95.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-665 Improper Initialization3
- CWE-20 Improper Input Validation3
- CWE-354 Improper Validation of Integrity Check Value2
- CWE-269 Improper Privilege Management2
- CWE-670 Always-Incorrect Control Flow Implementation2
- CWE-682 Incorrect Calculation2
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-39167No exploit | TimelockController vulnerability in OpenZeppelin Contractsopenzeppelin · contracts · CWE-269 | Critical9.8 | — | 1.6% | Aug 26, 2021 |
39Monitor | CVE-2021-39168No exploit | TimelockController vulnerability in OpenZeppelin Contractsopenzeppelin · contracts · CWE-269 | Critical9.8 | — | 1.6% | Aug 26, 2021 |
39Monitor | CVE-2021-41264No exploit | UUPSUpgradeable vulnerability in OpenZeppelin Contractsopenzeppelin · contracts · CWE-665 | Critical9.8 | — | 1.5% | Nov 12, 2021 |
35Monitor | CVE-2023-30542No exploit | GovernorCompatibilityBravo may trim proposal calldataopenzeppelin · contracts · CWE-20 | High8.8 | — | 0.6% | Apr 16, 2023 |
30Monitor | CVE-2021-46320No exploit | In OpenZeppelin <=v4.4.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal popenzeppelin · openzeppelin · CWE-665 | High7.5 | — | 1.2% | Feb 4, 2022 |
30Monitor | CVE-2022-31170No exploit | OpenZeppelin Contracts's ERC165Checker may revert instead of returning falseopenzeppelin · contracts · CWE-20 | High7.5 | — | 0.8% | Jul 22, 2022 |
30Monitor | CVE-2022-31198No exploit | GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals in @openzeppelin/contractsopenzeppelin · contracts · CWE-682 | High7.5 | — | 0.8% | Aug 1, 2022 |
30Monitor | CVE-2023-49798No exploit | Duplicated execution of subcalls in OpenZeppelin Contractsopenzeppelin · contracts · CWE-670 | High7.5 | — | 0.5% | Dec 8, 2023 |
30Monitor | CVE-2022-31172No exploit | OpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signersopenzeppelin · contracts · CWE-20 | High7.5 | — | 0.5% | Jul 22, 2022 |
29Monitor | CVE-2024-27094No exploit | OpenZeppelin Contracts base64 encoding may read from potentially dirty memoryopenzeppelin · contracts · CWE-125 | High7.4 | — | 0.8% | Mar 20, 2024 |
26Monitor | CVE-2022-31153No exploit | OpenZeppelin Contracts for Cairo account cannot process transactions on Goerliopenzeppelin · contracts · CWE-664 | Medium6.5 | — | 1.4% | Jul 15, 2022 |
26Monitor | CVE-2023-26488No exploit | OpenZeppelin Contracts contains Incorrect Calculationopenzeppelin · contracts · CWE-682 | Medium6.5 | — | 0.7% | Mar 3, 2023 |
26Monitor | CVE-2024-45304No exploit | OwnableTwoStep allows a pending owner to accept ownership after the original owner has renounced ownership in cairo-contractsopenzeppelin · contracts · CWE-670 | Medium6.5 | — | 0.5% | Aug 30, 2024 |
26Monitor | CVE-2022-35961No exploit | ECDSA signature malleability in OpenZeppelin Contractsopenzeppelin · contracts · CWE-354 | Medium6.5 | — | 0.4% | Aug 15, 2022 |
23Monitor | CVE-2023-34459No exploit | OpenZeppelin Contracts's MerkleProof multiproofs may allow proving arbitrary leaves for specific treesopenzeppelin · contracts · CWE-354 | Medium5.9 | — | 0.4% | Jun 16, 2023 |
22Monitor | CVE-2022-39384No exploit | OpenZeppelin Contracts initializer reentrancy may lead to double initializationopenzeppelin · contracts · CWE-665 | Medium5.6 | — | 0.5% | Nov 4, 2022 |
21Monitor | CVE-2023-30541No exploit | TransparentUpgradeableProxy clashing selector calls may not be delegated in @openzeppelin/contractsopenzeppelin · contracts · CWE-436 | Medium5.3 | — | 0.8% | Apr 17, 2023 |
21Monitor | CVE-2022-35915No exploit | Unbounded gas consumption in @openzeppelin/contractsopenzeppelin · contracts · CWE-400 | Medium5.3 | — | 0.8% | Aug 1, 2022 |
21Monitor | CVE-2023-40014No exploit | OpenZeppelin Contracts's ERC2771Context with custom forwarder may lead to zero-valued _msgSenderopenzeppelin · openzeppelin contracts · CWE-116 | Medium5.3 | — | 0.7% | Aug 10, 2023 |
21Monitor | CVE-2023-34234No exploit | Governor proposal creation may be blocked by frontrunning in OpenZeppelinopenzeppelin · contracts · CWE-862 | Medium5.3 | — | 0.6% | Jun 7, 2023 |
21Monitor | CVE-2022-35916No exploit | Cross chain utilities for Arbitrum L2 see EOA calls as cross chain callsopenzeppelin · contracts · CWE-669 | Medium5.3 | — | 0.6% | Aug 1, 2022 |
21Monitor | CVE-2023-23940No exploit | OpenZeppelin Contracts for Cairo is vulnerable to signature validation bypassopenzeppelin · contracts · CWE-345 | Medium5.3 | — | 0.2% | Feb 3, 2023 |
- CVE-2021-3916739Monitor
TimelockController vulnerability in OpenZeppelin Contracts
CriticalCVSS 9.8No exploitEPSS 2%openzeppelin · contractsAug 26, 2021
- CVE-2021-3916839Monitor
TimelockController vulnerability in OpenZeppelin Contracts
CriticalCVSS 9.8No exploitEPSS 2%openzeppelin · contractsAug 26, 2021
- CVE-2021-4126439Monitor
UUPSUpgradeable vulnerability in OpenZeppelin Contracts
CriticalCVSS 9.8No exploitEPSS 1%openzeppelin · contractsNov 12, 2021
- CVE-2023-3054235Monitor
GovernorCompatibilityBravo may trim proposal calldata
HighCVSS 8.8No exploitEPSS 1%openzeppelin · contractsApr 16, 2023
- CVE-2021-4632030Monitor
In OpenZeppelin <=v4.4.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal p
HighCVSS 7.5No exploitEPSS 1%openzeppelin · openzeppelinFeb 4, 2022
- CVE-2022-3117030Monitor
OpenZeppelin Contracts's ERC165Checker may revert instead of returning false
HighCVSS 7.5No exploitEPSS 1%openzeppelin · contractsJul 22, 2022
- CVE-2022-3119830Monitor
GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals in @openzeppelin/contracts
HighCVSS 7.5No exploitEPSS 1%openzeppelin · contractsAug 1, 2022
- CVE-2023-4979830Monitor
Duplicated execution of subcalls in OpenZeppelin Contracts
HighCVSS 7.5No exploitEPSS 1%openzeppelin · contractsDec 8, 2023
- CVE-2022-3117230Monitor
OpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signers
HighCVSS 7.5No exploitEPSS 0%openzeppelin · contractsJul 22, 2022
- CVE-2024-2709429Monitor
OpenZeppelin Contracts base64 encoding may read from potentially dirty memory
HighCVSS 7.4No exploitEPSS 1%openzeppelin · contractsMar 20, 2024
- CVE-2022-3115326Monitor
OpenZeppelin Contracts for Cairo account cannot process transactions on Goerli
MediumCVSS 6.5No exploitEPSS 1%openzeppelin · contractsJul 15, 2022
- CVE-2023-2648826Monitor
OpenZeppelin Contracts contains Incorrect Calculation
MediumCVSS 6.5No exploitEPSS 1%openzeppelin · contractsMar 3, 2023
- CVE-2024-4530426Monitor
OwnableTwoStep allows a pending owner to accept ownership after the original owner has renounced ownership in cairo-contracts
MediumCVSS 6.5No exploitEPSS 0%openzeppelin · contractsAug 30, 2024
- CVE-2022-3596126Monitor
ECDSA signature malleability in OpenZeppelin Contracts
MediumCVSS 6.5No exploitEPSS 0%openzeppelin · contractsAug 15, 2022
- CVE-2023-3445923Monitor
OpenZeppelin Contracts's MerkleProof multiproofs may allow proving arbitrary leaves for specific trees
MediumCVSS 5.9No exploitEPSS 0%openzeppelin · contractsJun 16, 2023
- CVE-2022-3938422Monitor
OpenZeppelin Contracts initializer reentrancy may lead to double initialization
MediumCVSS 5.6No exploitEPSS 1%openzeppelin · contractsNov 4, 2022
- CVE-2023-3054121Monitor
TransparentUpgradeableProxy clashing selector calls may not be delegated in @openzeppelin/contracts
MediumCVSS 5.3No exploitEPSS 1%openzeppelin · contractsApr 17, 2023
- CVE-2022-3591521Monitor
Unbounded gas consumption in @openzeppelin/contracts
MediumCVSS 5.3No exploitEPSS 1%openzeppelin · contractsAug 1, 2022
- CVE-2023-4001421Monitor
OpenZeppelin Contracts's ERC2771Context with custom forwarder may lead to zero-valued _msgSender
MediumCVSS 5.3No exploitEPSS 1%openzeppelin · openzeppelin contractsAug 10, 2023
- CVE-2023-3423421Monitor
Governor proposal creation may be blocked by frontrunning in OpenZeppelin
MediumCVSS 5.3No exploitEPSS 1%openzeppelin · contractsJun 7, 2023
- CVE-2022-3591621Monitor
Cross chain utilities for Arbitrum L2 see EOA calls as cross chain calls
MediumCVSS 5.3No exploitEPSS 1%openzeppelin · contractsAug 1, 2022
- CVE-2023-2394021Monitor
OpenZeppelin Contracts for Cairo is vulnerable to signature validation bypass
MediumCVSS 5.3No exploitEPSS 0%openzeppelin · contractsFeb 3, 2023