367 CVEs affecting OpenBSD products, 1 known to be exploited (CISA KEV), with EPSS scores. Most affected: OpenBSD, OpenSSH, Libressl, OpenSMTPD, Ftpd.