Записи bitwarden
14 опубликованных записей вендора bitwarden.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-862 Missing Authorization4
- CWE-303 Incorrect Implementation of Authentication Algorithm1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2026-60104Эксплойта нет | Bitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Requestbitwarden · server · CWE-639 | Критическая9,3 | — | 0,4 % | 8 июл. 2026 г. |
35Наблюдать | CVE-2026-43639Эксплойта нет | Bitwarden Server < 2026.4.0 Missing Authorization via Provider Clientsbitwarden · server · CWE-862 | Высокая8,9 | — | 0,8 % | 11 мая 2026 г. |
35Наблюдать | CVE-2026-42994Эксплойта нет | Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code.bitwarden · cli · CWE-78 | Высокая8,8 | — | 0,5 % | 1 мая 2026 г. |
34Наблюдать | CVE-2026-43640Эксплойта нет | Bitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Keybitwarden · server · CWE-303 | Высокая8,6 | — | 0,7 % | 11 мая 2026 г. |
31Наблюдать | CVE-2020-15879Эксплойта нет | Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: abitwarden · server · CWE-918 | Высокая7,5 | — | 2,7 % | 21 июл. 2020 г. |
30Наблюдать | CVE-2019-19766Эксплойта нет | The Bitwarden server through 1.32.0 has a potentially unwanted KDF.bitwarden · server · CWE-916 | Высокая7,5 | — | 1,3 % | 12 дек. 2019 г. |
30Наблюдать | CVE-2018-25081Эксплойта нет | Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element.bitwarden · bitwarden · CWE-200 | Высокая7,5 | — | 1,0 % | 8 мар. 2023 г. |
30Наблюдать | CVE-2023-27974Эксплойта нет | Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for an example.com hostinbitwarden · bitwarden | Высокая7,5 | — | 1,0 % | 8 мар. 2023 г. |
28Наблюдать | CVE-2026-57520Эксплойта нет | Bitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpointbitwarden · server · CWE-862 | Высокая7,1 | — | 0,6 % | 25 июн. 2026 г. |
28Наблюдать | CVE-2023-27706Эксплойта нет | Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other lobitwarden · bitwarden · CWE-312 | Высокая7,1 | — | 0,6 % | 9 июн. 2023 г. |
22Наблюдать | CVE-2023-38840Proof of concept | Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.bitwarden · bitwarden | Средняя5,5 | — | 0,5 % | 15 авг. 2023 г. |
21Наблюдать | CVE-2026-57521Эксплойта нет | Bitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceControllerbitwarden · server · CWE-862 | Средняя5,3 | — | 0,4 % | 25 июн. 2026 г. |
21Наблюдать | CVE-2026-43638Эксплойта нет | Bitwarden Server < 2026.4.1 Missing Authorization via Organization Cipher Importbitwarden · server · CWE-862 | Средняя5,3 | — | 0,3 % | 11 мая 2026 г. |
9Наблюдать | CVE-2026-57522Эксплойта нет | Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templatesbitwarden · server · CWE-74 | Низкая2,3 | — | 0,5 % | 25 июн. 2026 г. |
- CVE-2026-6010437Наблюдать
Bitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %bitwarden · server8 июл. 2026 г.
- CVE-2026-4363935Наблюдать
Bitwarden Server < 2026.4.0 Missing Authorization via Provider Clients
ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %bitwarden · server11 мая 2026 г.
- CVE-2026-4299435Наблюдать
Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bitwarden · cli1 мая 2026 г.
- CVE-2026-4364034Наблюдать
Bitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Key
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %bitwarden · server11 мая 2026 г.
- CVE-2020-1587931Наблюдать
Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: a
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %bitwarden · server21 июл. 2020 г.
- CVE-2019-1976630Наблюдать
The Bitwarden server through 1.32.0 has a potentially unwanted KDF.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bitwarden · server12 дек. 2019 г.
- CVE-2018-2508130Наблюдать
Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bitwarden · bitwarden8 мар. 2023 г.
- CVE-2023-2797430Наблюдать
Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for an example.com hostin
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bitwarden · bitwarden8 мар. 2023 г.
- CVE-2026-5752028Наблюдать
Bitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %bitwarden · server25 июн. 2026 г.
- CVE-2023-2770628Наблюдать
Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other lo
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %bitwarden · bitwarden9 июн. 2023 г.
- CVE-2023-3884022Наблюдать
Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.
СредняяCVSS 5,5Proof of conceptEPSS 1 %bitwarden · bitwarden15 авг. 2023 г.
- CVE-2026-5752121Наблюдать
Bitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceController
СредняяCVSS 5,3Эксплойта нетEPSS 0 %bitwarden · server25 июн. 2026 г.
- CVE-2026-4363821Наблюдать
Bitwarden Server < 2026.4.1 Missing Authorization via Organization Cipher Import
СредняяCVSS 5,3Эксплойта нетEPSS 0 %bitwarden · server11 мая 2026 г.
- CVE-2026-575229Наблюдать
Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templates
НизкаяCVSS 2,3Эксплойта нетEPSS 0 %bitwarden · server25 июн. 2026 г.