Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.00% | — | Escanav Escan Management Console | 20/8/2024 | 17/6/2026 | eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport. | |
| Modificada | Media (5.4) | 0.81% | — | Escanav Escan Management Console | 27/6/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Description parameter. | |
| Modificada | Media (5.4) | 0.81% | — | Escanav Escan Management Console | 27/6/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath. | |
| Modificada | Media (5.4) | 0.81% | — | Escanav Escan Management Console | 27/6/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters. | |
| Modificada | Media (5.4) | 0.76% | — | Escanav Escan Management Console | 27/6/2023 | 17/6/2026 | A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter. | |
| Modificada | Media (6.1) | 0.81% | — | Escanav Escan Management Console | 2/6/2023 | 17/6/2026 | Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the URL directly. | |
| Modificada | Media (6.1) | 0.84% | — | Escanav Escan Management Console | 31/5/2023 | 17/6/2026 | Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval. | |
| Modificada | Crítica (9.8) | 1.2% | — | Escanav Escan Management Console | 31/5/2023 | 17/6/2026 | Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format. | |
| Modificada | Crítica (9) | 4.5% | — | Escanav Escan Management Console | 17/5/2023 | 17/6/2026 | Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter. | |
| Modificada | Alta (7.2) | 4.3% | — | Escanav Escan Management Console | 17/5/2023 | 17/6/2026 | SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain windows XP command shell to perform code execution on database server via GetUserCurrentPwd?UsrId=1. | |
| Modificada | Media (5) | 3.1% | — | Microworld Technologies EscanMicroworld Technologies Escan Management ConsoleMicroworld Technologies Escan Server | 10/3/2008 | 16/6/2026 | Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Management Console (aka eScan Server) 9.0.742.1 allows remote attackers to read arbitrary files via an absolute pathname in the RETR (get) command. |