VYPR
Vendor

Keepassxc

Products
2
CVEs
5
Across products
5
Status
Private

Products

2

Recent CVEs

5
  • CVE-2026-4158HigApr 11, 2026
    risk 0.47cvss 7.3epss 0.00

    KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of KeePassXC. An attacker must first obtain the ability to execute low-privileged…

  • CVE-2024-33901MedMay 20, 2024
    risk 0.42cvss 6.5epss 0.01

    Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other…

  • CVE-2024-33900MedMay 20, 2024
    risk 0.42cvss 6.5epss 0.00

    KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.

  • CVE-2023-35866MedJun 19, 2023
    risk 0.36cvss 5.5epss 0.00

    In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the…

  • CVE-2025-65203HigDec 17, 2025
    risk 0.00cvss 7.1epss 0.00

    KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowing attacker-controlled script in the sandboxed document to access populated form fields and…