Skip to content
Noroxi

cryptomator records

10 published records for vendor cryptomator.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
70%
Median publish → KEV
No record has entered KEV

All records

10 records
  • Cryptomator: Hub unlocking accepts plaintext HTTP and unvalidated endpoint schemes

    HighCVSS 8.7No exploitEPSS 0%

    cryptomator · cryptomatorMar 20, 2026

  • Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.securit

    HighCVSS 7.8No exploitEPSS 1%

    cryptomator · cryptomatorFeb 18, 2022

  • Cryptomator vulnerable to Local Elevation of Privileges

    HighCVSS 7.8No exploitEPSS 0%

    cryptomator · cryptomatorAug 7, 2023

  • Cryptomator's MSI installer allows local privilege escalation

    HighCVSS 7.8No exploitEPSS 0%

    cryptomator · cryptomatorJul 25, 2023

  • Cryptomator: Tampered vault configuration allows MITM attack on Hub API

    MediumCVSS 5.9No exploitEPSS 0%

    cryptomator · cryptomatorMar 20, 2026

  • Cryptomator for IOS: Tampered vault configuration allows MITM attack on Hub API

    MediumCVSS 5.9No exploitEPSS 0%

    cryptomator · cryptomatorMar 20, 2026

  • Cryptomator for Android: Tampered vault configuration allows MITM attack on Hub API

    MediumCVSS 5.9No exploitEPSS 0%

    cryptomator · cryptomatorMar 20, 2026

  • Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths

    MediumCVSS 5.3No exploitEPSS 0%

    cryptomator · cryptomatorMar 20, 2026

  • Cryptomator: Leaking of cleartext paths into log file in non-debug mode

    MediumCVSS 5.3No exploitEPSS 0%

    cryptomator · cryptomatorMar 6, 2026

  • Cryptomator Hub OAuth token exchange HTTP downgrade via getAuthority() scheme confusion (CVE-2026-32303 bypass)

    MediumCVSS 4.8No exploitEPSS 0%

    cryptomator · cryptomatorApr 16, 2026