Vulnerabilities

Summary — last 7 days

New vulnerabilities2,826▼ 248 vs. last week
Critical / high1,321▼ 176 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (4.3)0.14%—Bsndev Ultimate Security CheckerAI3/28/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in bsndev Ultimate Security Checker ultimate-security-checker allows Cross Site Request Forgery.This issue affects Ultimate Security Checker: from n/a through <= 4.2.
ModifiedMedium (5)3.8%💥 ExploitSymantec Security Check Virus Detection12/31/20046/16/2026
rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function. NOTE: this issue was originally reported as a buffer overflow, but that specific claim is disputed by the vendor, although a crash is acknowledged.
ModifiedHigh (7.5)8.7%💥 ExploitSymantec Security Check8/7/20036/16/2026
Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security Check service, allows remote attackers to execute arbitrary code via a long argument to CompareVersionStrings.
Orbitaley — Vulnerabilities