VendorsLizardBytesunshineany version
Vulnerabilities

LizardByte Sunshine any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-32253
Sunshine: Authentication bypass via improper client certificate validation
Published 2026-05-22 · Analyzed
9.8EPSS 0.003
CVE-2025-53095
Sunshine application-wide CSRF in the UI leads to command injection as Administrator
Published 2025-07-01 · Analyzed
9.6EPSS 0.002
CVE-2024-51738
Sunshine improperly enforces pairing protocol request order
Published 2025-01-20 · Analyzed
8.1EPSS 0.006
CVE-2024-31220
Sunshine vulnerable to remote unauthenticated arbitrary file read
Published 2024-04-05 · Analyzed
7.3EPSS 0.005
CVE-2025-54081
SunshineService Has Unquoted Service Path That Allows Local SYSTEM Code Execution
Published 2025-09-23 · Analyzed
7.0EPSS 0.002
CVE-2025-53096
Sunshine clickjacking in the UI leads to unauthorized actions being performed
Published 2025-07-01 · Analyzed
6.1EPSS 0.002
CVE-2024-31221
Clients removed during unpairing process may regain access if Sunshine was not restarted
Published 2024-04-08 · Analyzed
5.9EPSS 0.005
CVE-2024-31226
Sunshine's unquoted executable path could lead to hijacked execution flow
Published 2024-05-16 · Analyzed
4.9EPSS 0.002