LizardByte kayıtları
lizardbyte üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %45,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-428 Unquoted Search Path or Element3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-300 Channel Accessible by Non-Endpoint1
- CWE-1021 Improper Restriction of Rendered UI Layers or Frames1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-32253İstismar yok | Sunshine: Authentication bypass via improper client certificate validationlizardbyte · sunshine · CWE-287 | Kritik9,8 | — | %0,4 | 22 May 2026 |
35İzleyin | CVE-2025-53095İstismar yok | Sunshine application-wide CSRF in the UI leads to command injection as Administratorlizardbyte · sunshine · CWE-352 | Yüksek8,8 | — | %0,2 | 30 Haz 2025 |
31İzleyin | CVE-2025-10198İstismar yok | LizardBytes Sunshine for Windows contains a DLL search-order hijacking vulnerabilitylizardbyte · sunshine · CWE-427 | Yüksek7,8 | — | %0,2 | 9 Eyl 2025 |
31İzleyin | CVE-2025-10199İstismar yok | A local privilege escalation vulnerability exists in LizardBytes' Sunshine for Windowslizardbyte · sunshine · CWE-428 | Yüksek7,8 | — | %0,2 | 9 Eyl 2025 |
30İzleyin | CVE-2024-51738İstismar yok | Sunshine improperly enforces pairing protocol request orderlizardbyte · sunshine · CWE-305 | Yüksek7,7 | — | %0,6 | 20 Oca 2025 |
29İzleyin | CVE-2024-31220İstismar yok | Sunshine vulnerable to remote unauthenticated arbitrary file readlizardbyte · sunshine · CWE-22 | Yüksek7,3 | — | %0,5 | 5 Nis 2024 |
28İzleyin | CVE-2025-54081İstismar yok | SunshineService Has Unquoted Service Path That Allows Local SYSTEM Code Executionlizardbyte · sunshine · CWE-428 | Yüksek7,0 | — | %0,2 | 23 Eyl 2025 |
24İzleyin | CVE-2025-53096İstismar yok | Sunshine clickjacking in the UI leads to unauthorized actions being performedlizardbyte · sunshine · CWE-1021 | Orta6,1 | — | %0,2 | 30 Haz 2025 |
23İzleyin | CVE-2024-31221İstismar yok | Clients removed during unpairing process may regain access if Sunshine was not restartedlizardbyte · sunshine · CWE-384 | Orta5,9 | — | %0,5 | 8 Nis 2024 |
21İzleyin | CVE-2024-45407İstismar yok | Sunshine has incorrect state management during pairing process may lead to incorrectly authorized clientlizardbyte · sunshine · CWE-300 | Orta5,3 | — | %0,3 | 10 Eyl 2024 |
11İzleyin | CVE-2024-31226İstismar yok | Sunshine's unquoted executable path could lead to hijacked execution flowlizardbyte · sunshine · CWE-428 | Düşük2,9 | — | %0,2 | 16 May 2024 |
- CVE-2026-3225339İzleyin
Sunshine: Authentication bypass via improper client certificate validation
KritikCVSS 9,8İstismar yokEPSS %0lizardbyte · sunshine22 May 2026
- CVE-2025-5309535İzleyin
Sunshine application-wide CSRF in the UI leads to command injection as Administrator
YüksekCVSS 8,8İstismar yokEPSS %0lizardbyte · sunshine30 Haz 2025
- CVE-2025-1019831İzleyin
LizardBytes Sunshine for Windows contains a DLL search-order hijacking vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0lizardbyte · sunshine9 Eyl 2025
- CVE-2025-1019931İzleyin
A local privilege escalation vulnerability exists in LizardBytes' Sunshine for Windows
YüksekCVSS 7,8İstismar yokEPSS %0lizardbyte · sunshine9 Eyl 2025
- CVE-2024-5173830İzleyin
Sunshine improperly enforces pairing protocol request order
YüksekCVSS 7,7İstismar yokEPSS %1lizardbyte · sunshine20 Oca 2025
- CVE-2024-3122029İzleyin
Sunshine vulnerable to remote unauthenticated arbitrary file read
YüksekCVSS 7,3İstismar yokEPSS %0lizardbyte · sunshine5 Nis 2024
- CVE-2025-5408128İzleyin
SunshineService Has Unquoted Service Path That Allows Local SYSTEM Code Execution
YüksekCVSS 7,0İstismar yokEPSS %0lizardbyte · sunshine23 Eyl 2025
- CVE-2025-5309624İzleyin
Sunshine clickjacking in the UI leads to unauthorized actions being performed
OrtaCVSS 6,1İstismar yokEPSS %0lizardbyte · sunshine30 Haz 2025
- CVE-2024-3122123İzleyin
Clients removed during unpairing process may regain access if Sunshine was not restarted
OrtaCVSS 5,9İstismar yokEPSS %1lizardbyte · sunshine8 Nis 2024
- CVE-2024-4540721İzleyin
Sunshine has incorrect state management during pairing process may lead to incorrectly authorized client
OrtaCVSS 5,3İstismar yokEPSS %0lizardbyte · sunshine10 Eyl 2024
- CVE-2024-3122611İzleyin
Sunshine's unquoted executable path could lead to hijacked execution flow
DüşükCVSS 2,9İstismar yokEPSS %0lizardbyte · sunshine16 May 2024