OpswatCVEs & Vulnerabilities

8 CVEs affecting Opswat products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

metadefender 4metadefender kiosk 3outpost security suite 2media validation agent 1
CVE-2024-57695HIGH

An issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to execute arbitrary code via the lock function. The manufacturer fixed the vulnerability in version 8.0 (4164.652.1856) from December 17, 2012.

11 Nov 2025
7.7
CVSS
CVE-2023-36659CRITICAL

An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Long inputs were not properly processed, which allows remote attackers to cause a denial of service (loss of communication).

15 Sep 2023
9.8
CVSS
CVE-2023-36657CRITICAL

An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrator) can be abused for privilege escalation.

15 Sep 2023
9.8
CVSS
CVE-2023-36658HIGH

An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally.

15 Sep 2023
7.8
CVSS
CVE-2022-40778MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability in OPSWAT MetaDefender ICAP Server before 4.13.0 allows attackers to execute arbitrary JavaScript or HTML because of the blocked page response.

19 Sep 2022
5.4
CVSS
CVE-2022-32272CRITICALpoc

OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.

9 Jun 2022
9.8
CVSS
CVE-2022-32273MEDIUM

As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server.

8 Jun 2022
4.3
CVSS
CVE-2018-16275HIGH

OPSWAT MetaDefender before v4.11.2 allows CSV injection.

31 Aug 2018
7.8
CVSS
← PrevPage 1 / 1Next →
Opswat CVEs & Vulnerabilities — 8 Tracked