CVE-2026-5492
- EPSS 1.6%
- Veröffentlicht 29.07.2026 19:10:14
- Zuletzt bearbeitet 30.07.2026 14:18:46
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The sp...
CVE-2026-5491
- EPSS 1.54%
- Veröffentlicht 29.07.2026 19:10:05
- Zuletzt bearbeitet 30.07.2026 14:18:46
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. Th...
CVE-2026-5490
- EPSS 0.48%
- Veröffentlicht 29.07.2026 19:09:57
- Zuletzt bearbeitet 31.07.2026 04:17:24
DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists ...
CVE-2026-5489
- EPSS 1.27%
- Veröffentlicht 29.07.2026 19:09:50
- Zuletzt bearbeitet 30.07.2026 14:18:46
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. Th...
CVE-2026-5487
- EPSS 1.54%
- Veröffentlicht 29.07.2026 19:09:41
- Zuletzt bearbeitet 30.07.2026 14:18:46
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. Th...
CVE-2025-67787
- EPSS 0.26%
- Veröffentlicht 17.12.2025 20:15:57
- Zuletzt bearbeitet 02.01.2026 15:55:01
An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network.
CVE-2025-67781
- EPSS 0.27%
- Veröffentlicht 17.12.2025 20:15:56
- Zuletzt bearbeitet 02.01.2026 15:55:28
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileged processes to gain more privileges on Windows computers.
CVE-2025-67789
- EPSS 0.22%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 19:42:04
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer count of other DriveLock tenants via the DriveLock API.
CVE-2025-67790
- EPSS 0.32%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 20:16:08
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged user could cause occasionally a Blue Screen Of Death (BSOD) on Windows computers by using an IOCTL and an unterminated string.
CVE-2025-67792
- EPSS 0.13%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 20:16:08
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate a DriveLock process to execute arbitrary commands on Windows computers.