element records
7 published records for vendor element.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 42.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-357 Insufficient UI Warning of Dangerous Operations1
- CWE-416 Use After Free1
- CWE-488 Exposure of Data Element to Wrong Session1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2022-23597No exploit | Remote program execution with user interactionelement · desktop · CWE-416 | High8.8 | — | 1.5% | Feb 1, 2022 |
31Monitor | CVE-2024-26131No exploit | Element Android Intent Redirectionelement · element · CWE-923 | High7.8 | — | 0.5% | Feb 28, 2024 |
27Monitor | CVE-2026-45078No exploit | Synapse CPU starvation (Denial of Service)element · synapse · CWE-770 | Medium6.8 | — | 0.1% | May 28, 2026 |
26Monitor | CVE-2022-41904No exploit | Element iOS is vulnerable due to missing decoration for events decrypted with untrusted Megolm sessionselement · element · CWE-357 | Medium6.5 | — | 0.4% | Nov 11, 2022 |
20Monitor | CVE-2026-45076No exploit | Synapse pagination denial of serviceelement · synapse · CWE-20 | Medium5.1 | — | 0.4% | May 28, 2026 |
18Monitor | CVE-2025-27606No exploit | Element Android PIN autologout bypasselement · element · CWE-488 | Medium4.6 | — | 0.2% | Mar 14, 2025 |
13Monitor | CVE-2024-26132No exploit | Element Android can be asked to share internal files.element · element · CWE-200 | Low3.3 | — | 0.4% | Feb 28, 2024 |
- CVE-2022-2359735Monitor
Remote program execution with user interaction
HighCVSS 8.8No exploitEPSS 1%element · desktopFeb 1, 2022
- CVE-2024-2613131Monitor
Element Android Intent Redirection
HighCVSS 7.8No exploitEPSS 0%element · elementFeb 28, 2024
- CVE-2026-4507827Monitor
Synapse CPU starvation (Denial of Service)
MediumCVSS 6.8No exploitEPSS 0%element · synapseMay 28, 2026
- CVE-2022-4190426Monitor
Element iOS is vulnerable due to missing decoration for events decrypted with untrusted Megolm sessions
MediumCVSS 6.5No exploitEPSS 0%element · elementNov 11, 2022
- CVE-2026-4507620Monitor
Synapse pagination denial of service
MediumCVSS 5.1No exploitEPSS 0%element · synapseMay 28, 2026
- CVE-2025-2760618Monitor
Element Android PIN autologout bypass
MediumCVSS 4.6No exploitEPSS 0%element · elementMar 14, 2025
- CVE-2024-2613213Monitor
Element Android can be asked to share internal files.
LowCVSS 3.3No exploitEPSS 0%element · elementFeb 28, 2024