Drbuho's vulnerability footprint is concentrated in system-utility products such as BuhoCleanser and BuhoNTFS, with observed exposures centered on permission-assignment and file-system access-control issues including incorrect permission assignment for critical resources and time-of-check time-of-use race conditions. These weakness patterns reflect the privileged, filesystem-touching nature of cleanup and storage-management utilities; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Drbuho over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13733HIGH BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoNTFS: 1.3.2. | Dec 12, 2025 | 7.8 | 26 | NO | NO |
CVE-2026-0924HIGH BuhoCleaner contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoCleaner: 1.15. | Feb 2, 2026 | 7.0 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Drbuho.
Media articles that mention a CVE ID that affects a product developed by Drbuho — matched by CVE ID, not by vendor name.