Products: 2
    Vulnerabilities: 10
    Known Exploited: 0
    0
    Critical Level Threats
    6
    High Level Threats
    3
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-86776

    KeePass 2.35 through 2.61.1 Memory Exhaustion via KDBX Header Field Size

    Last Modified: Sep 10, 2026
    Published: Sep 09, 2026

    CVE-2020-37178

    KeePass 2.44 - Denial of Service (PoC)

    Last Modified: Apr 15, 2026
    Published: Feb 11, 2026

    CVE-2023-32784

    In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be a KeePass process dump, swap file (pagefile.sys), hibernation file (hiberfil.sys), or RAM dump of the entire system. The first character cannot be recovered. In 2.54, there is different API usage and/or random string insertion for mitigation.

    Last Modified: Jan 23, 2025
    Published: May 15, 2023

    CVE-2023-24055

    KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.

    Last Modified: Nov 21, 2024
    Published: Jan 22, 2023

    CVE-2022-0725

    A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.

    Last Modified: Nov 21, 2024
    Published: Mar 07, 2022
    Items Per Page