wire records
29 published records for vendor wire.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 17.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-134 Use of Externally-Controlled Format String3
- CWE-755 Improper Handling of Exceptional Conditions2
- CWE-20 Improper Input Validation2
- CWE-285 Improper Authorization2
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
29 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-27853No exploit | Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a forwire · wire · CWE-134 | Critical9.8 | — | 3.9% | Oct 27, 2020 |
40Plan | CVE-2021-41193No exploit | Use of Externally-Controlled Format String in wire-avswire · wire-audio video signaling · CWE-134 | Critical9.8 | — | 2.5% | Mar 1, 2022 |
39Monitor | CVE-2021-41093No exploit | Account takeover when having only access to a user's short lived tokenwire · wire · CWE-285 | Critical9.8 | — | 1.5% | Oct 4, 2021 |
39Monitor | CVE-2021-41100No exploit | Account takeover when having only access to a user's short lived token in wire-serverwire · wire-server · CWE-285 | Critical9.8 | — | 0.9% | Oct 4, 2021 |
38Monitor | CVE-2021-21382No exploit | Unsafe loopback forwarding interface in Restundwire · restund · CWE-668 | Critical9.6 | — | 1.5% | Jun 11, 2021 |
35Monitor | CVE-2023-48221No exploit | wire-avs remote format string vulnerabilitywire · audio\, video\, and signaling · CWE-134 | High8.8 | — | 0.9% | Nov 20, 2023 |
33Monitor | CVE-2020-15258No exploit | Insecure use of shell.openExternal in Wirewire · wire · CWE-20 | High8.0 | — | 2.1% | Oct 16, 2020 |
32Monitor | CVE-2022-23610No exploit | Improper Verification of Cryptographic Signature in wire-serverwire · wire-server · CWE-347 | High8.1 | — | 0.7% | Mar 16, 2022 |
32Monitor | CVE-2022-31122No exploit | Wire-server vulnerable to Token Recipient Confusion resulting in account impersonation, deletion or malicious account creationwire · wire server · CWE-287 | High8.1 | — | 0.7% | Oct 18, 2022 |
30Monitor | CVE-2018-8909No exploit | The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a wire · wire · CWE-22 | High7.5 | — | 1.6% | Mar 22, 2018 |
30Monitor | CVE-2021-41119No exploit | DoS vulnerabiliity in wire-server json parserwire · wire-server · CWE-400 | High7.5 | — | 1.4% | Apr 13, 2022 |
26Monitor | CVE-2022-23625No exploit | DoS vulnerability: Malformed Resource Identifierswire · wire · CWE-755 | Medium6.5 | — | 1.2% | Mar 11, 2022 |
26Monitor | CVE-2021-21400No exploit | Entering code in App Lock modal sends input to conversationwire · wire-webapp · CWE-200 | Medium6.5 | — | 1.1% | Apr 2, 2021 |
26Monitor | CVE-2021-21396No exploit | Bulk list client endpoint exposes too much metadata about a clientwire · wire server · CWE-200 | Medium6.5 | — | 1.1% | Mar 26, 2021 |
26Monitor | CVE-2021-32666No exploit | Asset DoS vulnerabilitywire · wire · CWE-20 | Medium6.5 | — | 0.9% | Jun 3, 2021 |
26Monitor | CVE-2023-22737No exploit | wire-server vulnerable to unauthorized removal of Bots from Conversationswire · wire · CWE-280 | Medium6.5 | — | 0.7% | Jan 27, 2023 |
26Monitor | CVE-2022-31009No exploit | DoS vulnerability: Invalid Accent Colorswire · wire · CWE-617 | Medium6.5 | — | 0.7% | Jun 23, 2022 |
26Monitor | CVE-2021-32665No exploit | Verified groups not reliablewire · wire · CWE-345 | Medium6.5 | — | 0.5% | Jun 3, 2021 |
24Monitor | CVE-2022-24799No exploit | Cross Site Scripting in Wire Webappwire · wire-webapp · CWE-79 | Medium6.1 | — | 1.0% | Apr 20, 2022 |
24Monitor | CVE-2022-29168No exploit | Cross Site Scripting in Wire Messageswire · wire-webapp · CWE-79 | Medium6.1 | — | 0.8% | Jun 25, 2022 |
24Monitor | CVE-2021-32683No exploit | XSS through createObjectURLwire · wire-webapp · CWE-79 | Medium6.1 | — | 0.8% | Jun 15, 2021 |
22Monitor | CVE-2021-41101No exploit | CORS `Access-Control-Allow-Origin` settings are too lenientwire · wire server · CWE-79 | Medium5.7 | — | 0.7% | Sep 30, 2021 |
22Monitor | CVE-2025-48066No exploit | wire-webapp has no database deletion on client logoutwire · wire-webapp · CWE-226 | Medium5.5 | — | 0.1% | May 22, 2025 |
21Monitor | CVE-2022-39380No exploit | wire-webapp contains Improper Handling of Exceptional Conditions leading to a DoS via Markdown Renderingwire · wire-webapp · CWE-755 | Medium5.3 | — | 0.6% | Jan 27, 2023 |
18Monitor | CVE-2022-43673No exploit | Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of wire · wire · CWE-532 | Medium4.7 | — | 0.3% | Nov 18, 2022 |
- CVE-2020-2785340Plan
Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a for
CriticalCVSS 9.8No exploitEPSS 4%wire · wireOct 27, 2020
- CVE-2021-4119340Plan
Use of Externally-Controlled Format String in wire-avs
CriticalCVSS 9.8No exploitEPSS 2%wire · wire-audio video signalingMar 1, 2022
- CVE-2021-4109339Monitor
Account takeover when having only access to a user's short lived token
CriticalCVSS 9.8No exploitEPSS 1%wire · wireOct 4, 2021
- CVE-2021-4110039Monitor
Account takeover when having only access to a user's short lived token in wire-server
CriticalCVSS 9.8No exploitEPSS 1%wire · wire-serverOct 4, 2021
- CVE-2021-2138238Monitor
Unsafe loopback forwarding interface in Restund
CriticalCVSS 9.6No exploitEPSS 1%wire · restundJun 11, 2021
- CVE-2023-4822135Monitor
wire-avs remote format string vulnerability
HighCVSS 8.8No exploitEPSS 1%wire · audio\, video\, and signalingNov 20, 2023
- CVE-2020-1525833Monitor
Insecure use of shell.openExternal in Wire
HighCVSS 8.0No exploitEPSS 2%wire · wireOct 16, 2020
- CVE-2022-2361032Monitor
Improper Verification of Cryptographic Signature in wire-server
HighCVSS 8.1No exploitEPSS 1%wire · wire-serverMar 16, 2022
- CVE-2022-3112232Monitor
Wire-server vulnerable to Token Recipient Confusion resulting in account impersonation, deletion or malicious account creation
HighCVSS 8.1No exploitEPSS 1%wire · wire serverOct 18, 2022
- CVE-2018-890930Monitor
The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a
HighCVSS 7.5No exploitEPSS 2%wire · wireMar 22, 2018
- CVE-2021-4111930Monitor
DoS vulnerabiliity in wire-server json parser
HighCVSS 7.5No exploitEPSS 1%wire · wire-serverApr 13, 2022
- CVE-2022-2362526Monitor
DoS vulnerability: Malformed Resource Identifiers
MediumCVSS 6.5No exploitEPSS 1%wire · wireMar 11, 2022
- CVE-2021-2140026Monitor
Entering code in App Lock modal sends input to conversation
MediumCVSS 6.5No exploitEPSS 1%wire · wire-webappApr 2, 2021
- CVE-2021-2139626Monitor
Bulk list client endpoint exposes too much metadata about a client
MediumCVSS 6.5No exploitEPSS 1%wire · wire serverMar 26, 2021
- CVE-2021-3266626Monitor
Asset DoS vulnerability
MediumCVSS 6.5No exploitEPSS 1%wire · wireJun 3, 2021
- CVE-2023-2273726Monitor
wire-server vulnerable to unauthorized removal of Bots from Conversations
MediumCVSS 6.5No exploitEPSS 1%wire · wireJan 27, 2023
- CVE-2022-3100926Monitor
DoS vulnerability: Invalid Accent Colors
MediumCVSS 6.5No exploitEPSS 1%wire · wireJun 23, 2022
- CVE-2021-3266526Monitor
Verified groups not reliable
MediumCVSS 6.5No exploitEPSS 0%wire · wireJun 3, 2021
- CVE-2022-2479924Monitor
Cross Site Scripting in Wire Webapp
MediumCVSS 6.1No exploitEPSS 1%wire · wire-webappApr 20, 2022
- CVE-2022-2916824Monitor
Cross Site Scripting in Wire Messages
MediumCVSS 6.1No exploitEPSS 1%wire · wire-webappJun 25, 2022
- CVE-2021-3268324Monitor
XSS through createObjectURL
MediumCVSS 6.1No exploitEPSS 1%wire · wire-webappJun 15, 2021
- CVE-2021-4110122Monitor
CORS `Access-Control-Allow-Origin` settings are too lenient
MediumCVSS 5.7No exploitEPSS 1%wire · wire serverSep 30, 2021
- CVE-2025-4806622Monitor
wire-webapp has no database deletion on client logout
MediumCVSS 5.5No exploitEPSS 0%wire · wire-webappMay 22, 2025
- CVE-2022-3938021Monitor
wire-webapp contains Improper Handling of Exceptional Conditions leading to a DoS via Markdown Rendering
MediumCVSS 5.3No exploitEPSS 1%wire · wire-webappJan 27, 2023
- CVE-2022-4367318Monitor
Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of
MediumCVSS 4.7No exploitEPSS 0%wire · wireNov 18, 2022