LizardByte records
11 published records for vendor lizardbyte.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 45.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-428 Unquoted Search Path or Element3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-300 Channel Accessible by Non-Endpoint1
- CWE-1021 Improper Restriction of Rendered UI Layers or Frames1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-32253No exploit | Sunshine: Authentication bypass via improper client certificate validationlizardbyte · sunshine · CWE-287 | Critical9.8 | — | 0.4% | May 22, 2026 |
35Monitor | CVE-2025-53095No exploit | Sunshine application-wide CSRF in the UI leads to command injection as Administratorlizardbyte · sunshine · CWE-352 | High8.8 | — | 0.2% | Jun 30, 2025 |
31Monitor | CVE-2025-10198No exploit | LizardBytes Sunshine for Windows contains a DLL search-order hijacking vulnerabilitylizardbyte · sunshine · CWE-427 | High7.8 | — | 0.2% | Sep 9, 2025 |
31Monitor | CVE-2025-10199No exploit | A local privilege escalation vulnerability exists in LizardBytes' Sunshine for Windowslizardbyte · sunshine · CWE-428 | High7.8 | — | 0.2% | Sep 9, 2025 |
30Monitor | CVE-2024-51738No exploit | Sunshine improperly enforces pairing protocol request orderlizardbyte · sunshine · CWE-305 | High7.7 | — | 0.6% | Jan 20, 2025 |
29Monitor | CVE-2024-31220No exploit | Sunshine vulnerable to remote unauthenticated arbitrary file readlizardbyte · sunshine · CWE-22 | High7.3 | — | 0.5% | Apr 5, 2024 |
28Monitor | CVE-2025-54081No exploit | SunshineService Has Unquoted Service Path That Allows Local SYSTEM Code Executionlizardbyte · sunshine · CWE-428 | High7.0 | — | 0.2% | Sep 23, 2025 |
24Monitor | CVE-2025-53096No exploit | Sunshine clickjacking in the UI leads to unauthorized actions being performedlizardbyte · sunshine · CWE-1021 | Medium6.1 | — | 0.2% | Jun 30, 2025 |
23Monitor | CVE-2024-31221No exploit | Clients removed during unpairing process may regain access if Sunshine was not restartedlizardbyte · sunshine · CWE-384 | Medium5.9 | — | 0.5% | Apr 8, 2024 |
21Monitor | CVE-2024-45407No exploit | Sunshine has incorrect state management during pairing process may lead to incorrectly authorized clientlizardbyte · sunshine · CWE-300 | Medium5.3 | — | 0.3% | Sep 10, 2024 |
11Monitor | CVE-2024-31226No exploit | Sunshine's unquoted executable path could lead to hijacked execution flowlizardbyte · sunshine · CWE-428 | Low2.9 | — | 0.2% | May 16, 2024 |
- CVE-2026-3225339Monitor
Sunshine: Authentication bypass via improper client certificate validation
CriticalCVSS 9.8No exploitEPSS 0%lizardbyte · sunshineMay 22, 2026
- CVE-2025-5309535Monitor
Sunshine application-wide CSRF in the UI leads to command injection as Administrator
HighCVSS 8.8No exploitEPSS 0%lizardbyte · sunshineJun 30, 2025
- CVE-2025-1019831Monitor
LizardBytes Sunshine for Windows contains a DLL search-order hijacking vulnerability
HighCVSS 7.8No exploitEPSS 0%lizardbyte · sunshineSep 9, 2025
- CVE-2025-1019931Monitor
A local privilege escalation vulnerability exists in LizardBytes' Sunshine for Windows
HighCVSS 7.8No exploitEPSS 0%lizardbyte · sunshineSep 9, 2025
- CVE-2024-5173830Monitor
Sunshine improperly enforces pairing protocol request order
HighCVSS 7.7No exploitEPSS 1%lizardbyte · sunshineJan 20, 2025
- CVE-2024-3122029Monitor
Sunshine vulnerable to remote unauthenticated arbitrary file read
HighCVSS 7.3No exploitEPSS 0%lizardbyte · sunshineApr 5, 2024
- CVE-2025-5408128Monitor
SunshineService Has Unquoted Service Path That Allows Local SYSTEM Code Execution
HighCVSS 7.0No exploitEPSS 0%lizardbyte · sunshineSep 23, 2025
- CVE-2025-5309624Monitor
Sunshine clickjacking in the UI leads to unauthorized actions being performed
MediumCVSS 6.1No exploitEPSS 0%lizardbyte · sunshineJun 30, 2025
- CVE-2024-3122123Monitor
Clients removed during unpairing process may regain access if Sunshine was not restarted
MediumCVSS 5.9No exploitEPSS 1%lizardbyte · sunshineApr 8, 2024
- CVE-2024-4540721Monitor
Sunshine has incorrect state management during pairing process may lead to incorrectly authorized client
MediumCVSS 5.3No exploitEPSS 0%lizardbyte · sunshineSep 10, 2024
- CVE-2024-3122611Monitor
Sunshine's unquoted executable path could lead to hijacked execution flow
LowCVSS 2.9No exploitEPSS 0%lizardbyte · sunshineMay 16, 2024