Waycrate's vulnerability footprint centers on swhkd, a niche but specialized hotkey-daemon product whose disclosures skew toward serious outcomes with an elevated tendency toward critical severity. The recurring weakness classes—resource-exposure and link-following flaws, along with resource-allocation and observable-discrepancy issues—reflect the security-sensitive nature of a system-level input handler operating at a privileged boundary. Defenders managing systems that run this daemon should prioritize tracking and applying patches; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Waycrate over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27818CRITICAL SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service. | Apr 7, 2022 | 9.1 | 29 | NO | NO |
CVE-2022-27815HIGH SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service. | Mar 30, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-27816HIGH SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service. | Mar 30, 2022 | 7.1 | 24 | NO | NO |
CVE-2022-27819MEDIUM SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon an attempt to parse a large or | Apr 7, 2022 | 5.3 | 20 | NO | NO |
CVE-2022-27817MEDIUM SWHKD 1.1.5 consumes the keyboard events of unintended users. This could potentially cause an information leak, but is usually a denial of functionality. | Apr 14, 2022 | 4.4 | 18 | NO | NO |
SWHKD 1.1.5 allows arbitrary file-existence tests via the -c option. | Apr 14, 2022 | 3.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Waycrate.
Media articles that mention a CVE ID that affects a product developed by Waycrate — matched by CVE ID, not by vendor name.