Vulnerabilities > Trezor

DATE CVE VULNERABILITY TITLE RISK
2021-07-26 CVE-2020-18172 Code Injection vulnerability in Trezor Bridge 2.0.27
A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges.
network
low complexity
trezor CWE-94
critical
9.8
2019-08-08 CVE-2019-14353 Information Exposure Through Discrepancy vulnerability in Trezor ONE Firmware
On Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found.
high complexity
trezor CWE-203
4.2