KeePass records
8 published records for vendor keepass.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-319 Cleartext Transmission of Sensitive Information1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2023-32784Proof of concept | In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or nkeepass · keepass · CWE-319 | High7.5 | — | 4.4% | May 15, 2023 |
31Monitor | CVE-2022-0725Proof of concept | A flaw was found in keepass.keepass · keepass · CWE-200 | High7.5 | — | 2.5% | Mar 10, 2022 |
31Monitor | CVE-2016-5119No exploit | The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the versiokeepass · keepass · CWE-20 | High7.5 | — | 2.3% | Jan 23, 2017 |
31Monitor | CVE-2019-20184No exploit | KeePass 2.4.1 allows CSV injection in the title field of a CSV export.keepass · keepass · CWE-1236 | High7.8 | — | 1.6% | Jan 9, 2020 |
30Monitor | CVE-2017-1000066No exploit | The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, which may result in thekeepass · keepass | High7.5 | — | 1.4% | Jul 17, 2017 |
27Monitor | CVE-2010-5196No exploit | Untrusted search path vulnerability in KeePass Password Safe before 2.13 allows local users to gain privileges via a Trojan horse DwmApi.dllkeepass · password safe | Medium6.9 | — | 0.6% | Sep 6, 2012 |
27Monitor | CVE-2010-5200No exploit | Untrusted search path vulnerability in KeePass Password Safe before 1.18 allows local users to gain privileges via a Trojan horse DLL in thekeepass · keepass | Medium6.9 | — | 0.4% | Sep 6, 2012 |
23Monitor | CVE-2023-24055Proof of concept | KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the clearkeepass · keepass · CWE-312 | Medium5.5 | — | 3.7% | Jan 22, 2023 |
- CVE-2023-3278431Monitor
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or n
HighCVSS 7.5Proof of conceptEPSS 4%keepass · keepassMay 15, 2023
- CVE-2022-072531Monitor
A flaw was found in keepass.
HighCVSS 7.5Proof of conceptEPSS 2%keepass · keepassMar 10, 2022
- CVE-2016-511931Monitor
The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the versio
HighCVSS 7.5No exploitEPSS 2%keepass · keepassJan 23, 2017
- CVE-2019-2018431Monitor
KeePass 2.4.1 allows CSV injection in the title field of a CSV export.
HighCVSS 7.8No exploitEPSS 2%keepass · keepassJan 9, 2020
- CVE-2017-100006630Monitor
The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, which may result in the
HighCVSS 7.5No exploitEPSS 1%keepass · keepassJul 17, 2017
- CVE-2010-519627Monitor
Untrusted search path vulnerability in KeePass Password Safe before 2.13 allows local users to gain privileges via a Trojan horse DwmApi.dll
MediumCVSS 6.9No exploitEPSS 1%keepass · password safeSep 6, 2012
- CVE-2010-520027Monitor
Untrusted search path vulnerability in KeePass Password Safe before 1.18 allows local users to gain privileges via a Trojan horse DLL in the
MediumCVSS 6.9No exploitEPSS 0%keepass · keepassSep 6, 2012
- CVE-2023-2405523Monitor
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the clear
MediumCVSS 5.5Proof of conceptEPSS 4%keepass · keepassJan 22, 2023