Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

225 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.62%—Microworld Escan AVAI19/9/202517/6/2026
MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were delivered and accepted without robust cryptographic verification. As a result, an on-path attacker could perform a man-in-the-middle (MitM) attack and substitute malicious update payloads for legitimate…
AnalizadaCrítica (9.3)0.79%—Mmaitre314 Picklescan17/9/202525/9/2026
A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check. This is possible because the scanner performs an exact match for module names, allowing malicious payloads to be loaded via submodules of dangerous…
AnalizadaCrítica (9.3)1.5%—Mmaitre314 Picklescan17/9/202525/9/2026
An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans. This is achieved by crafting a ZIP archive containing a file with a bad Cyclic Redundancy Check (CRC), which causes the scanner to halt and fail…
AnalizadaCrítica (9.3)0.85%—Mmaitre314 Picklescan17/9/202525/9/2026
An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the pickle file incorrectly considered safe is…
AplazadaCrítica (9.4)4.7%💥 ExploitEscan WEB Management ConsoleAI25/7/202517/6/2026
A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' parameter when processing login requests to login.php, allowing an authenticated attacker with a valid username to inject arbitrary commands via a specially crafted password…
AnalizadaMedia (6.8)0.22%—Mmaitre314 Picklescan24/4/202517/6/2026
The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.
ModificadaMedia (5.3)0.55%—Mmaitre314 Picklescan10/3/202517/6/2026
picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flipping specific bits in the ZIP file headers, an attacker can embed malicious pickle files that remain undetected by PickleScan while still being successfully loaded by…
ModificadaMedia (5.3)0.33%—Mmaitre314 Picklescan10/3/202517/6/2026
picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model archives. By modifying the filename in the ZIP header while keeping the original filename in the directory listing, an attacker can make PickleScan raise a BadZipFile…
ModificadaMedia (5.3)0.40%—Mmaitre314 Picklescan3/3/202517/6/2026
picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and include a malicious pickle file with a non-standard file extension. Because the malicious pickle file inclusion is not considered as part of…
ModificadaMedia (5.3)1.7%💥 PoCMmaitre314 Picklescan26/2/202517/6/2026
picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on pypi.org or GitHub) via `pip.main()`. Because pip is not a restricted global, the model, when scanned with picklescan, would pass…
AnalizadaMedia (4.8)2.4%—Escanav Escan Anti-virus17/2/202517/6/2026
A vulnerability, which was classified as critical, has been found in MicroWorld eScan Antivirus 7.0.32 on Linux. Affected by this issue is the function sprintf of the file epsdaemon of the component Autoscan USB. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has…
AnalizadaBaja (2)3.0%—Escanav Escan Anti-virus17/2/202517/6/2026
A vulnerability classified as critical was found in MicroWord eScan Antivirus 7.0.32 on Linux. Affected by this vulnerability is an unknown functionality of the component USB Password Handler. The manipulation leads to os command injection. The attack needs to be approached locally. The complexity of an attack is…
AnalizadaMedia (4.6)0.43%—Escanav Escan Anti-virus17/2/202517/6/2026
A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects the function ReadConfiguration of the file /opt/MicroWorld/etc/mwav.conf. The manipulation of the argument BasePath leads to buffer overflow. Local access is required to approach this…
AnalizadaMedia (4.8)0.36%—Escanav Escan Anti-virus17/2/202517/6/2026
A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux. It has been classified as critical. This affects the function sprintf of the component USB Password Handler. The manipulation leads to buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure…
AnalizadaMedia (4.8)0.34%—Escanav Escan Anti-virus17/2/202517/6/2026
A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this issue is the function strcpy of the component VirusPopUp. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public…
AnalizadaMedia (4.8)0.37%—Escanav Escan Anti-virus16/2/202517/6/2026
A vulnerability has been found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this vulnerability is the function passPrompt of the component USB Protection Service. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The…
AnalizadaCrítica (9.2)6.9%—Escanav Escan Anti-virus29/1/202517/6/2026
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the component Quarantine Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The complexity of an attack…
AnalizadaMedia (4.8)0.30%—Escanav Escan Anti-virus29/1/202517/6/2026
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been declared as problematic. This vulnerability affects unknown code of the file /var/Microworld/ of the component Quarantine Handler. The manipulation leads to incorrect default permissions. The attack needs to be approached locally. The…
AnalizadaMedia (4.8)0.21%—Escanav Escan Anti-virus26/1/202517/6/2026
A vulnerability was found in Microword eScan Antivirus 7.0.32 on Linux. It has been rated as problematic. Affected by this issue is the function removeExtraSlashes of the file /opt/MicroWorld/sbin/rtscanner of the component Folder Watch List Handler. The manipulation leads to stack-based buffer overflow. The attack…
AnalizadaMedia (4.8)0.29%—Escanav Escan Anti-virus8/1/202517/6/2026
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. Affected by this issue is some unknown functionality of the file /opt/MicroWorld/var/ of the component Installation Handler. The manipulation leads to incorrect default permissions. The attack needs to be approached…
AnalizadaCrítica (9.8)1.00%💥 PoCEscanav Escan Management Console20/8/202417/6/2026
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
AplazadaAlta (7.8)0.18%—Microworld Technologies Escan AntivirusAI3/5/202417/6/2026
A kernel handle leak issue in ProcObsrvesx.sys 4.0.0.49 in MicroWorld Technologies Inc eScan Antivirus could allow privilege escalation for low-privileged users.
ModificadaAlta (7.8)4.2%💥 ExploitLenovo DiagnosticsLenovo Hardwarescan AddinLenovo Hardwarescan Plugin25/10/202317/6/2026
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.
ModificadaMedia (4.4)0.21%—Lenovo DiagnosticsLenovo Hardwarescan Plugin25/10/202317/6/2026
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash.
ModificadaMedia (4.4)0.21%—Lenovo DiagnosticsLenovo Hardwarescan AddinLenovo Hardwarescan Plugin25/10/202317/6/2026
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash.
Orbitaley — Vulnerabilidades