VYPR

Vendor CVEs

Escanav

All CVEs

28 total · sorted by risk
  • CVE-2024-42919CriAug 20, 2024
    risk 0.64cvss 9.8epss 0.01

    eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

  • CVE-2023-33730CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.

  • CVE-2018-18388CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.02

    eScan Agent Application (MWAGENT.EXE) 4.0.2.98 in MicroWorld Technologies eScan 14.0 allows remote or local attackers to execute arbitrary commands by sending a carefully crafted payload to TCP port 2222.

  • CVE-2023-31703CriMay 17, 2023
    risk 0.62cvss 9.0epss 0.04

    Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.

  • CVE-2025-0798HigJan 29, 2025
    risk 0.53cvss 8.1epss 0.07

    A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the component Quarantine Handler. The manipulation leads to os command injection. The attack may be…

  • CVE-2023-4383HigAug 16, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. This affects an unknown part of the file runasroot. The manipulation leads to incorrect execution-assigned permissions. The attack needs to be approached locally. The…

  • CVE-2021-26624HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.02

    An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroot" command. This vulnerability can induce remote attackers to exploit root…

  • CVE-2018-6203HigJan 25, 2018
    risk 0.51cvss 7.8epss 0.00

    In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300210C.

  • CVE-2018-6202HigJan 25, 2018
    risk 0.51cvss 7.8epss 0.00

    In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020F8.

  • CVE-2018-6201HigJan 25, 2018
    risk 0.51cvss 7.8epss 0.00

    In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020E0 or 0x830020E4.

  • CVE-2023-31702HigMay 17, 2023
    risk 0.50cvss 7.2epss 0.04

    SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain windows XP command shell to perform code execution on database server via GetUserCurrentPwd?UsrId=1.

  • CVE-2023-33731MedJun 2, 2023
    risk 0.40cvss 6.1epss 0.01

    Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the URL directly.

  • CVE-2023-33732MedMay 31, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval.

  • CVE-2023-2875MedMay 24, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability, which was classified as problematic, was found in eScan Antivirus 22.0.1400.2443. Affected is the function 0x22E008u in the library PROCOBSRVESX.SYS of the component IoControlCode Handler. The manipulation leads to null pointer dereference. It is possible to…

  • CVE-2018-10098MedJul 13, 2018
    risk 0.36cvss 5.5epss 0.00

    In MicroWorld eScan Internet Security Suite (ISS) for Business 14.0.1400.2029, the driver econceal.sys allows a non-privileged user to send a 0x830020E0 IOCTL request to \\.\econceal to cause a denial of service (BSOD).

  • CVE-2025-1370MedFeb 17, 2025
    risk 0.35cvss 5.3epss 0.02

    A vulnerability, which was classified as critical, has been found in MicroWorld eScan Antivirus 7.0.32 on Linux. Affected by this issue is the function sprintf of the file epsdaemon of the component Autoscan USB. The manipulation leads to os command injection. An attack has to…

  • CVE-2023-34838MedJun 27, 2023
    risk 0.35cvss 5.4epss 0.01

    A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Description parameter.

  • CVE-2023-34837MedJun 27, 2023
    risk 0.35cvss 5.4epss 0.01

    A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath.

  • CVE-2023-34836MedJun 27, 2023
    risk 0.35cvss 5.4epss 0.01

    A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters.

  • CVE-2023-34835MedJun 27, 2023
    risk 0.35cvss 5.4epss 0.01

    A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.

  • CVE-2025-1367MedFeb 17, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been classified as critical. This affects the function sprintf of the component USB Password Handler. The manipulation leads to buffer overflow. An attack has to be approached locally. The vendor was…

  • CVE-2025-1366MedFeb 17, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this issue is the function strcpy of the component VirusPopUp. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. The…

  • CVE-2025-1364MedFeb 16, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this vulnerability is the function passPrompt of the component USB Protection Service. The manipulation leads to stack-based buffer overflow. It is possible to…

  • CVE-2024-13188MedJan 8, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. Affected by this issue is some unknown functionality of the file /opt/MicroWorld/var/ of the component Installation Handler. The manipulation leads to incorrect default…

  • CVE-2025-1369MedFeb 17, 2025
    risk 0.30cvss 4.5epss 0.03

    A vulnerability classified as critical was found in MicroWord eScan Antivirus 7.0.32 on Linux. Affected by this vulnerability is an unknown functionality of the component USB Password Handler. The manipulation leads to os command injection. The attack needs to be approached…

  • CVE-2025-0797LowJan 29, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects unknown code of the file /var/Microworld/ of the component Quarantine Handler. The manipulation leads to incorrect default permissions. The…

  • CVE-2025-0720LowJan 26, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in Microword eScan Antivirus 7.0.32 on Linux. It has been rated as problematic. Affected by this issue is the function removeExtraSlashes of the file /opt/MicroWorld/sbin/rtscanner of the component Folder Watch List Handler. The manipulation leads to…

  • CVE-2025-1368LowFeb 17, 2025
    risk 0.15cvss 2.3epss 0.00

    A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects the function ReadConfiguration of the file /opt/MicroWorld/etc/mwav.conf. The manipulation of the argument BasePath leads to buffer overflow.…