Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-23988

    Rufus has Local Privilege Escalation via TOCTOU Race Condition in Fido Script Handling

    Last Modified: Apr 18, 2026
    Published: Jan 22, 2026

    CVE-2019-1010101

    Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The component is: Executable installer, portable executable (ALL executables available). The attack vector is: CWE-29, CWE-377, CWE-379.

    Last Modified: Nov 21, 2024
    Published: Jul 19, 2019

    CVE-2019-1010100

    Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code execution WITH escalation of privilege. The component is: Executable installers, portable executables (ALL executables on the web site). The attack vector is: CAPEC-471, CWE-426, CWE-427.

    Last Modified: Nov 21, 2024
    Published: Jul 19, 2019

    CVE-2017-13083

    Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code

    Last Modified: Apr 07, 2026
    Published: Oct 18, 2017
    Items Per Page