22 CVEs affecting Rsyslog products, 0 known to be exploited (CISA KEV), with EPSS scores. Most affected: Rsyslog, Librelp, Rsyslogd.