cryptomator records
10 published records for vendor cryptomator.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 70%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-346 Origin Validation Error3
- CWE-269 Improper Privilege Management2
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-426 Untrusted Search Path1
- CWE-305 Authentication Bypass by Primary Weakness1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2026-32309No exploit | Cryptomator: Hub unlocking accepts plaintext HTTP and unvalidated endpoint schemescryptomator · cryptomator · CWE-319 | High8.7 | — | 0.3% | Mar 20, 2026 |
31Monitor | CVE-2022-25366No exploit | Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.securitcryptomator · cryptomator · CWE-426 | High7.8 | — | 0.6% | Feb 18, 2022 |
31Monitor | CVE-2023-39520No exploit | Cryptomator vulnerable to Local Elevation of Privilegescryptomator · cryptomator · CWE-269 | High7.8 | — | 0.3% | Aug 7, 2023 |
31Monitor | CVE-2023-37907No exploit | Cryptomator's MSI installer allows local privilege escalationcryptomator · cryptomator · CWE-269 | High7.8 | — | 0.2% | Jul 25, 2023 |
23Monitor | CVE-2026-32303No exploit | Cryptomator: Tampered vault configuration allows MITM attack on Hub APIcryptomator · cryptomator · CWE-346 | Medium5.9 | — | 0.2% | Mar 20, 2026 |
23Monitor | CVE-2026-32318No exploit | Cryptomator for IOS: Tampered vault configuration allows MITM attack on Hub APIcryptomator · cryptomator · CWE-346 | Medium5.9 | — | 0.1% | Mar 20, 2026 |
23Monitor | CVE-2026-32317No exploit | Cryptomator for Android: Tampered vault configuration allows MITM attack on Hub APIcryptomator · cryptomator · CWE-346 | Medium5.9 | — | 0.1% | Mar 20, 2026 |
21Monitor | CVE-2026-32310No exploit | Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC pathscryptomator · cryptomator · CWE-22 | Medium5.3 | — | 0.4% | Mar 20, 2026 |
21Monitor | CVE-2026-29110No exploit | Cryptomator: Leaking of cleartext paths into log file in non-debug modecryptomator · cryptomator · CWE-209 | Medium5.3 | — | 0.2% | Mar 6, 2026 |
19Monitor | CVE-2026-33472No exploit | Cryptomator Hub OAuth token exchange HTTP downgrade via getAuthority() scheme confusion (CVE-2026-32303 bypass)cryptomator · cryptomator · CWE-305 | Medium4.8 | — | 0.1% | Apr 16, 2026 |
- CVE-2026-3230934Monitor
Cryptomator: Hub unlocking accepts plaintext HTTP and unvalidated endpoint schemes
HighCVSS 8.7No exploitEPSS 0%cryptomator · cryptomatorMar 20, 2026
- CVE-2022-2536631Monitor
Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.securit
HighCVSS 7.8No exploitEPSS 1%cryptomator · cryptomatorFeb 18, 2022
- CVE-2023-3952031Monitor
Cryptomator vulnerable to Local Elevation of Privileges
HighCVSS 7.8No exploitEPSS 0%cryptomator · cryptomatorAug 7, 2023
- CVE-2023-3790731Monitor
Cryptomator's MSI installer allows local privilege escalation
HighCVSS 7.8No exploitEPSS 0%cryptomator · cryptomatorJul 25, 2023
- CVE-2026-3230323Monitor
Cryptomator: Tampered vault configuration allows MITM attack on Hub API
MediumCVSS 5.9No exploitEPSS 0%cryptomator · cryptomatorMar 20, 2026
- CVE-2026-3231823Monitor
Cryptomator for IOS: Tampered vault configuration allows MITM attack on Hub API
MediumCVSS 5.9No exploitEPSS 0%cryptomator · cryptomatorMar 20, 2026
- CVE-2026-3231723Monitor
Cryptomator for Android: Tampered vault configuration allows MITM attack on Hub API
MediumCVSS 5.9No exploitEPSS 0%cryptomator · cryptomatorMar 20, 2026
- CVE-2026-3231021Monitor
Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths
MediumCVSS 5.3No exploitEPSS 0%cryptomator · cryptomatorMar 20, 2026
- CVE-2026-2911021Monitor
Cryptomator: Leaking of cleartext paths into log file in non-debug mode
MediumCVSS 5.3No exploitEPSS 0%cryptomator · cryptomatorMar 6, 2026
- CVE-2026-3347219Monitor
Cryptomator Hub OAuth token exchange HTTP downgrade via getAuthority() scheme confusion (CVE-2026-32303 bypass)
MediumCVSS 4.8No exploitEPSS 0%cryptomator · cryptomatorApr 16, 2026