Plasma-workspace
7 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Plasma-workspace, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Plasma-workspace CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 7 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High1
- Medium5
- Low1
Latest CVEs
The 7 most recently published vulnerabilities affecting Plasma-workspace.
- CVE-2024-36041KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local connections are accepted. This ...7.8
- CVE-2024-1433KDE Plasma Workspace Theme File eventpluginsmanager.cpp enabledPlugins path traversal3.1
- CVE-2018-6791An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted ...6.8
- CVE-2018-6790An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification,...5.3
- CVE-2016-2312Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.6.8
- CVE-2015-1307plasma-workspace before 5.1.95 allows remote attackers to obtain passwords via a Trojan horse Look and Feel package.4.3
- CVE-2015-1308kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is loc...4.3
Product grouping is registry-driven, with AI assist and human review. How it works