Sunshine
Vendor:
First CVE: Apr 5, 2024 · Active for 2 years
11
Total CVEs
More Total CVEs than 89% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sunshine over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 5, 2024
2 years ago
Most Recent CVE
May 22, 2026
63 days ago
CVE Severity & Scoring
Sunshine11 CVEs
9%
27%
55%
9%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (36.4%)
Network7 (63.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (54.5%)
High5 (45.5%)
Unknown0 (0.0%)
User Interaction
None5 (45.5%)
Unknown0 (0.0%)
Required6 (54.5%)
Privileges Required
Low3 (27.3%)
High1 (9.1%)
None7 (63.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32253CRITICAL Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verific | May 22, 2026 | 9.8 | 36 | NO | NO |
CVE-2025-10199HIGH A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path. | Sep 9, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-10198HIGH Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories | Sep 9, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-53095HIGH Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. | Jul 1, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-54081HIGH Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sun | Sep 23, 2025 | 7.0 | 23 | NO | NO |
CVE-2024-51738HIGH Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerabl | Jan 20, 2025 | 8.1 | 22 | NO | NO |
CVE-2024-31220HIGH Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely read arbitrary files without a | Apr 5, 2024 | 7.3 | 21 | NO | NO |
CVE-2025-53096MEDIUM Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability a | Jul 1, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-45407MEDIUM Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client ra | Sep 10, 2024 | 5.3 | 16 | NO | NO |
CVE-2024-31221MEDIUM Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairi | Apr 8, 2024 | 5.9 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Sunshine
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2025.122.141614 | 2 | 7.8 | 0.2% | 0 | 0 |
| 2024-05-27 | 1 | 5.3 | 0.3% | 0 | 0 |