Sunshine

Vendor:

First CVE: Apr 5, 2024 · Active for 2 years

11
Total CVEs
More Total CVEs than 89% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Sunshine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 5, 2024
2 years ago
Most Recent CVE
May 22, 2026
63 days ago

CVE Severity & Scoring

Sunshine11 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local4 (36.4%)
Network7 (63.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (54.5%)
High5 (45.5%)
Unknown0 (0.0%)
User Interaction
None5 (45.5%)
Unknown0 (0.0%)
Required6 (54.5%)
Privileges Required
Low3 (27.3%)
High1 (9.1%)
None7 (63.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verific
May 22, 20269.836NONO
A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path.
Sep 9, 20257.825NONO
Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories
Sep 9, 20257.825NONO
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks.
Jul 1, 20258.825NONO
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sun
Sep 23, 20257.023NONO
Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerabl
Jan 20, 20258.122NONO
Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely read arbitrary files without a
Apr 5, 20247.321NONO
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability a
Jul 1, 20256.119NONO
Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client ra
Sep 10, 20245.316NONO
Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web UI interface and then pairi
Apr 8, 20245.916NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Sunshine

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2025.122.14161427.80.2%00
2024-05-2715.30.3%00