Absolute records
60 published records for vendor absolute.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 76.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-276 Incorrect Default Permissions5
- CWE-121 Stack-based Buffer Overflow5
- CWE-20 Improper Input Validation5
- CWE-400 Uncontrolled Resource Consumption5
- CWE-284 Improper Access Control4
The weakness classes this vendor ships most often: where to look.
CWEAll records
60 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2018-16715No exploit | An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479.absolute · ctes windows agent · CWE-732 | High8.8 | — | 0.9% | Sep 8, 2018 |
34Monitor | CVE-2026-33445No exploit | Memory management vulnerability in Secure Access serversabsolute · secure access · CWE-400 | High8.7 | — | 0.4% | Jul 15, 2026 |
34Monitor | CVE-2026-55402No exploit | CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57.absolute · secure access · CWE-125 | High8.7 | — | 0.4% | Aug 13, 2026 |
34Monitor | CVE-2025-49080No exploit | Memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54absolute · secure access · CWE-762 | High8.7 | — | 0.4% | Jun 12, 2025 |
34Monitor | CVE-2026-33451No exploit | Arbitrary read/write vulnerability in Windows clients prior to 14.50absolute · secure access · CWE-125 | High8.5 | — | 0.2% | Apr 30, 2026 |
34Monitor | CVE-2026-40952No exploit | Privilge misconfiguration in Secure Access installersabsolute · secure access · CWE-276 | High8.5 | — | 0.1% | Jul 15, 2026 |
33Monitor | CVE-2024-40872No exploit | Elevation of privilege in Absolute Secure Access clients and serversabsolute security · secure access · CWE-822 | High8.4 | — | 0.2% | Jul 25, 2024 |
32Monitor | CVE-2025-59595No exploit | CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12.absolute · secure access · CWE-20 | High8.2 | — | 0.3% | Nov 4, 2025 |
28Monitor | CVE-2026-40950No exploit | Buffer overflow in the Secure Access server prior to 14.50absolute · secure access · CWE-121 | High7.1 | — | 0.4% | Apr 30, 2026 |
28Monitor | CVE-2026-33443No exploit | Memory management error in Secure Access servers prior to 14.55absolute · secure access · CWE-400 | High7.1 | — | 0.4% | Jul 15, 2026 |
28Monitor | CVE-2025-49083No exploit | Data deserialization vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.56absolute · secure access · CWE-502 | High7.0 | — | 0.4% | Jul 30, 2025 |
28Monitor | CVE-2025-27703No exploit | Privilege escalation in the management console of Absolute Secure Access prior to version 13.54absolute · secure access · CWE-281 | High7.0 | — | 0.3% | May 28, 2025 |
27Monitor | CVE-2025-49081No exploit | Input validation vulnerability in the Secure Access prior to version 13.55absolute · secure access · CWE-20 | Medium6.9 | — | 0.5% | Jun 12, 2025 |
27Monitor | CVE-2026-55401No exploit | CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57.absolute · secure access · CWE-476 | Medium6.9 | — | 0.4% | Aug 13, 2026 |
27Monitor | CVE-2026-33444No exploit | Memory management vulnerability in Secure Access serversabsolute · secure access · CWE-119 | Medium6.9 | — | 0.4% | Jul 15, 2026 |
27Monitor | CVE-2026-55398No exploit | Memory management vulnerability in Secure Access clientsabsolute · secure access · CWE-119 | Medium6.9 | — | 0.4% | Jul 15, 2026 |
27Monitor | CVE-2025-27702No exploit | Permissions bypass in the management console of Absolute Secure Access prior to version 13.54absolute · secure access · CWE-284 | Medium6.9 | — | 0.3% | May 28, 2025 |
27Monitor | CVE-2024-6364No exploit | Server Identity Validation Bypass in Absolute Persistence®absolute · persistence · CWE-284 | Medium6.9 | — | 0.2% | May 13, 2025 |
27Monitor | CVE-2026-40949No exploit | Buffer overflow in Windows clients prior to 14.50absolute · secure access · CWE-121 | Medium6.8 | — | 0.1% | Apr 30, 2026 |
27Monitor | CVE-2026-40951No exploit | Memory corruption in Secure Access Windows clients prior to 14.50absolute · secure access · CWE-400 | Medium6.8 | — | 0.1% | Apr 30, 2026 |
26Monitor | CVE-2009-5150No exploit | Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set uabsolute · computrace agent · CWE-284 | Medium6.7 | — | 0.5% | May 11, 2018 |
26Monitor | CVE-2009-5151No exploit | The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signatabsolute · computrace agent · CWE-284 | Medium6.7 | — | 0.5% | May 11, 2018 |
26Monitor | CVE-2026-40953No exploit | Heap overflow in Secure Access clientsabsolute · secure access · CWE-787 | Medium6.7 | — | 0.1% | Jul 15, 2026 |
24Monitor | CVE-2026-40957No exploit | Frameable content vulnerability in the Secure Access server login pageabsolute · secure access · CWE-1021 | Medium6.1 | — | 0.4% | Jul 15, 2026 |
24Monitor | CVE-2026-55400No exploit | CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57.absolute · secure access · CWE-190 | Medium6.0 | — | 0.4% | Aug 13, 2026 |
- CVE-2018-1671535Monitor
An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479.
HighCVSS 8.8No exploitEPSS 1%absolute · ctes windows agentSep 8, 2018
- CVE-2026-3344534Monitor
Memory management vulnerability in Secure Access servers
HighCVSS 8.7No exploitEPSS 0%absolute · secure accessJul 15, 2026
- CVE-2026-5540234Monitor
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57.
HighCVSS 8.7No exploitEPSS 0%absolute · secure accessAug 13, 2026
- CVE-2025-4908034Monitor
Memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54
HighCVSS 8.7No exploitEPSS 0%absolute · secure accessJun 12, 2025
- CVE-2026-3345134Monitor
Arbitrary read/write vulnerability in Windows clients prior to 14.50
HighCVSS 8.5No exploitEPSS 0%absolute · secure accessApr 30, 2026
- CVE-2026-4095234Monitor
Privilge misconfiguration in Secure Access installers
HighCVSS 8.5No exploitEPSS 0%absolute · secure accessJul 15, 2026
- CVE-2024-4087233Monitor
Elevation of privilege in Absolute Secure Access clients and servers
HighCVSS 8.4No exploitEPSS 0%absolute security · secure accessJul 25, 2024
- CVE-2025-5959532Monitor
CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12.
HighCVSS 8.2No exploitEPSS 0%absolute · secure accessNov 4, 2025
- CVE-2026-4095028Monitor
Buffer overflow in the Secure Access server prior to 14.50
HighCVSS 7.1No exploitEPSS 0%absolute · secure accessApr 30, 2026
- CVE-2026-3344328Monitor
Memory management error in Secure Access servers prior to 14.55
HighCVSS 7.1No exploitEPSS 0%absolute · secure accessJul 15, 2026
- CVE-2025-4908328Monitor
Data deserialization vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.56
HighCVSS 7.0No exploitEPSS 0%absolute · secure accessJul 30, 2025
- CVE-2025-2770328Monitor
Privilege escalation in the management console of Absolute Secure Access prior to version 13.54
HighCVSS 7.0No exploitEPSS 0%absolute · secure accessMay 28, 2025
- CVE-2025-4908127Monitor
Input validation vulnerability in the Secure Access prior to version 13.55
MediumCVSS 6.9No exploitEPSS 0%absolute · secure accessJun 12, 2025
- CVE-2026-5540127Monitor
CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57.
MediumCVSS 6.9No exploitEPSS 0%absolute · secure accessAug 13, 2026
- CVE-2026-3344427Monitor
Memory management vulnerability in Secure Access servers
MediumCVSS 6.9No exploitEPSS 0%absolute · secure accessJul 15, 2026
- CVE-2026-5539827Monitor
Memory management vulnerability in Secure Access clients
MediumCVSS 6.9No exploitEPSS 0%absolute · secure accessJul 15, 2026
- CVE-2025-2770227Monitor
Permissions bypass in the management console of Absolute Secure Access prior to version 13.54
MediumCVSS 6.9No exploitEPSS 0%absolute · secure accessMay 28, 2025
- CVE-2024-636427Monitor
Server Identity Validation Bypass in Absolute Persistence®
MediumCVSS 6.9No exploitEPSS 0%absolute · persistenceMay 13, 2025
- CVE-2026-4094927Monitor
Buffer overflow in Windows clients prior to 14.50
MediumCVSS 6.8No exploitEPSS 0%absolute · secure accessApr 30, 2026
- CVE-2026-4095127Monitor
Memory corruption in Secure Access Windows clients prior to 14.50
MediumCVSS 6.8No exploitEPSS 0%absolute · secure accessApr 30, 2026
- CVE-2009-515026Monitor
Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set u
MediumCVSS 6.7No exploitEPSS 1%absolute · computrace agentMay 11, 2018
- CVE-2009-515126Monitor
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signat
MediumCVSS 6.7No exploitEPSS 0%absolute · computrace agentMay 11, 2018
- CVE-2026-4095326Monitor
Heap overflow in Secure Access clients
MediumCVSS 6.7No exploitEPSS 0%absolute · secure accessJul 15, 2026
- CVE-2026-4095724Monitor
Frameable content vulnerability in the Secure Access server login page
MediumCVSS 6.1No exploitEPSS 0%absolute · secure accessJul 15, 2026
- CVE-2026-5540024Monitor
CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57.
MediumCVSS 6.0No exploitEPSS 0%absolute · secure accessAug 13, 2026