Skip to content
Noroxi

LizardByte records

11 published records for vendor lizardbyte.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
45.5%
Median publish → KEV
No record has entered KEV

All records

11 records
  • Sunshine: Authentication bypass via improper client certificate validation

    CriticalCVSS 9.8No exploitEPSS 0%

    lizardbyte · sunshineMay 22, 2026

  • Sunshine application-wide CSRF in the UI leads to command injection as Administrator

    HighCVSS 8.8No exploitEPSS 0%

    lizardbyte · sunshineJun 30, 2025

  • LizardBytes Sunshine for Windows contains a DLL search-order hijacking vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    lizardbyte · sunshineSep 9, 2025

  • A local privilege escalation vulnerability exists in LizardBytes' Sunshine for Windows

    HighCVSS 7.8No exploitEPSS 0%

    lizardbyte · sunshineSep 9, 2025

  • Sunshine improperly enforces pairing protocol request order

    HighCVSS 7.7No exploitEPSS 1%

    lizardbyte · sunshineJan 20, 2025

  • Sunshine vulnerable to remote unauthenticated arbitrary file read

    HighCVSS 7.3No exploitEPSS 0%

    lizardbyte · sunshineApr 5, 2024

  • SunshineService Has Unquoted Service Path That Allows Local SYSTEM Code Execution

    HighCVSS 7.0No exploitEPSS 0%

    lizardbyte · sunshineSep 23, 2025

  • Sunshine clickjacking in the UI leads to unauthorized actions being performed

    MediumCVSS 6.1No exploitEPSS 0%

    lizardbyte · sunshineJun 30, 2025

  • Clients removed during unpairing process may regain access if Sunshine was not restarted

    MediumCVSS 5.9No exploitEPSS 1%

    lizardbyte · sunshineApr 8, 2024

  • Sunshine has incorrect state management during pairing process may lead to incorrectly authorized client

    MediumCVSS 5.3No exploitEPSS 0%

    lizardbyte · sunshineSep 10, 2024

  • Sunshine's unquoted executable path could lead to hijacked execution flow

    LowCVSS 2.9No exploitEPSS 0%

    lizardbyte · sunshineMay 16, 2024