CVE-2024-33901: Keepassxc
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.
Affected products
- Keepassxc Keepassxc: version 2.7.7 only
Published 2024-05-20. Last modified 2026-06-17.