Vulnerabilities > Keepass > Keepass > 1.10

DATE CVE VULNERABILITY TITLE RISK
2023-01-22 CVE-2023-24055 Cleartext Storage of Sensitive Information vulnerability in Keepass
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger.
local
low complexity
keepass CWE-312
5.5
2017-01-23 CVE-2016-5119 Improper Input Validation vulnerability in Keepass
The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check response and supplying a crafted update.
network
high complexity
keepass CWE-20
5.1
2012-09-06 CVE-2010-5200 Unspecified vulnerability in Keepass
Untrusted search path vulnerability in KeePass Password Safe before 1.18 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .kdb file.
local
keepass
6.9