CVE-2026-57850
- EPSS 0.42%
- Veröffentlicht 10.07.2026 19:53:21
- Zuletzt bearbeitet 11.08.2026 14:17:14
RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for ...
CVE-2026-58056
- EPSS 0.19%
- Veröffentlicht 28.06.2026 02:16:32
- Zuletzt bearbeitet 18.07.2026 21:17:03
RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboa...
CVE-2026-30785
- EPSS 0.08%
- Veröffentlicht 05.03.2026 16:16:19
- Zuletzt bearbeitet 25.03.2026 15:47:08
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Pas...
CVE-2026-30783
- EPSS 0.38%
- Veröffentlicht 05.03.2026 16:16:18
- Zuletzt bearbeitet 22.06.2026 14:16:35
A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated with program ...
CVE-2026-30789
- EPSS 0.27%
- Veröffentlicht 05.03.2026 15:41:51
- Zuletzt bearbeitet 22.06.2026 14:16:36
Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, peer authent...
CVE-2026-30798
- EPSS 0.29%
- Veröffentlicht 05.03.2026 15:38:49
- Zuletzt bearbeitet 22.06.2026 10:16:22
Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) all...
CVE-2026-30797
- EPSS 0.46%
- Veröffentlicht 05.03.2026 15:35:08
- Zuletzt bearbeitet 25.03.2026 16:16:29
Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) allows Application API Message Manipulation via Man-in-the-Middle. This ...
CVE-2026-30796
- EPSS 0.41%
- Veröffentlicht 05.03.2026 15:30:39
- Zuletzt bearbeitet 19.07.2026 12:16:48
Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Snif...
CVE-2026-30795
- EPSS 0.27%
- Veröffentlicht 05.03.2026 15:27:16
- Zuletzt bearbeitet 25.03.2026 15:25:40
Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with progr...
CVE-2026-30794
- EPSS 0.31%
- Veröffentlicht 05.03.2026 15:24:34
- Zuletzt bearbeitet 22.06.2026 14:17:10
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.