Known Vulnerabilities for Server by Bitwarden
Listed below are 9 of the newest known vulnerabilities associated with "Server" by "Bitwarden".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-78682 json | NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, ... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-78555 json | RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-78551 json | RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enume... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-78417 json | Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and ea... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-78414 json | Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windo... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-78385 json | RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents are con... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-78321 json | The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker ... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-78277 json | Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions. | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-78269 json | Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions. | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-78255 json | The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating... | Not Provided | 2026-08-24 | 2026-08-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Bitwarden | Server | 1.9.0 | |||
| Application | Bitwarden | Server | 1.8.2 | |||
| Application | Bitwarden | Server | 1.8.1 | |||
| Application | Bitwarden | Server | 1.8.0 | |||
| Application | Bitwarden | Server | 1.7.0 | |||
| Application | Bitwarden | Server | 1.6.0 | |||
| Application | Bitwarden | Server | 1.5.1 | |||
| Application | Bitwarden | Server | 1.5.0 | |||
| Application | Bitwarden | Server | 1.4.1 | |||
| Application | Bitwarden | Server | 1.4.0 | |||
| Application | Bitwarden | Server | 1.35.1 | |||
| Application | Bitwarden | Server | 1.32.0 | |||
| Application | Bitwarden | Server | 1.31.1 | |||
| Application | Bitwarden | Server | 1.31.0 | |||
| Application | Bitwarden | Server | 1.30.4 | |||
| Application | Bitwarden | Server | 1.30.3 | |||
| Application | Bitwarden | Server | 1.30.2 | |||
| Application | Bitwarden | Server | 1.30.1 | |||
| Application | Bitwarden | Server | 1.30.0 | |||
| Application | Bitwarden | Server | 1.3.4 |