VYPR

Vendor CVEs

Absolute

All CVEs

66 total · sorted by risk
  • CVE-2025-54087LowOct 2, 2025
    risk 0.17cvss 2.6epss 0.00

    CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity is high, there are no attack…

  • CVE-2007-6268Dec 7, 2007
    risk 0.04cvss epss 0.08

    Directory traversal vulnerability in pages/default.aspx in Absolute News Manager.NET 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

  • CVE-2008-6858Jul 14, 2009
    risk 0.03cvss epss 0.03

    Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

  • CVE-2026-55399MedJul 15, 2026
    risk 0.00cvss 4.3epss 0.00

    CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher.

  • CVE-2026-55398LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.

  • CVE-2026-33445MedJul 15, 2026
    risk 0.00cvss 5.9epss 0.00

    CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.

  • CVE-2026-33444LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against the server.

  • CVE-2026-40958LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

  • CVE-2026-40957HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.00

    o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site could use it to potentially steal credentials from an unwary administrator.

  • CVE-2026-40956LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can cause a small amount of random memory to leak.

  • CVE-2026-40955LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.

  • CVE-2026-40954LowJul 15, 2026
    risk 0.00cvss 3.7epss 0.00

    CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client

  • CVE-2026-40953MedJul 15, 2026
    risk 0.00cvss 4.4epss 0.00

    CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control.

  • CVE-2026-40952HigJul 15, 2026
    risk 0.00cvss 7.8epss 0.00

    CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a…

  • CVE-2026-33443MedJul 15, 2026
    risk 0.00cvss 5.9epss 0.00

    CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.

  • CVE-2006-1416Mar 28, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in afmsearch.aspx in Absolute FAQ Manager .NET 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the question parameter.

Page 2 of 2