openzeppelin
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 26 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 26, 2021 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
OpenZeppelin Confidential Contracts ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds.
OpenZeppelin Contracts's Bytes's lastIndexOf function with position argument performs out-of-bound memory access on empty buffers
OwnableTwoStep allows a pending owner to accept ownership after the original owner has renounced ownership in cairo-contracts
OpenZeppelin Contracts base64 encoding may read from potentially dirty memory
Duplicated execution of subcalls in OpenZeppelin Contracts
Multiple NFT collections at risk by flaw in open-source library
OpenZeppelin Contracts's ERC2771Context with custom forwarder may lead to zero-valued _msgSender
OpenZeppelin Contracts's MerkleProof multiproofs may allow proving arbitrary leaves for specific trees
Governor proposal creation may be blocked by frontrunning in OpenZeppelin
Monitor openzeppelin in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.