E
ExpressVPN
Security Risk Profile
31
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 6 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 2, 2019 to present
6
Total CVEs
3
Critical+High
0
Exploited
3
Unpatched
Threat Assessment
Avg CVSS
7.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
31/100
low
Severity Distribution
Critical
0High
3Medium
0Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
Integer Overflow
1
2
Buffer Overflow
1
3
Path Traversal
1
Most Affected Products
1. ExpressVPN Windows3
2. ExpressVPN ExpressVPN2
3. ExpressVPN Windows client1
4. Zoom Windows apps1
5. Fortra GoAnywhere MFT1
Recent Vulnerabilities
See more →https://www.bleepingcomputer.com/news/security/expressvpn-bug-leaked-user-ips-in-remote-desktop-sessions/
unknown
ExpressVPN bug leaked user IPs in Remote Desktop sessions
Jul 21, 2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/white-house-urges-devs-to-switch-to-memory-safe-programming-languages/
unknown
White House urges devs to switch to memory-safe programming languages
Feb 26, 2024🔧 No Patch
https://www.bleepingcomputer.com/news/security/expressvpn-bug-has-been-leaking-some-dns-requests-for-years/
unknown
ExpressVPN bug has been leaking some DNS requests for years
Feb 11, 2024🔧 No Patch
CVE-2024-25728
CVSS 7.5EPSS 0%high
Feb 11, 2024🔧 No Patch
CVE-2020-29238
CVSS 7.5high
Mar 10, 2021🔧 No Patch
CVE-2018-15490
CVSS 7.1high
Jan 2, 2019🔧 No Patch
Monitor ExpressVPN in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.