threat
engine
.sh
Back
·
··:··
Home
/
Product
/
eset security
Product
eset security
22 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2024-3779
< 11.0.15004.0
Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render E
6.1
MEDIUM
CVE-2024-1619
>= 8.0 and <= 8.0.3.30
Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could pot
6.1
MEDIUM
CVE-2024-0353
< 7.3.15006.0
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files withou
7.8
HIGH
CVE-2023-5594
all versions
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate sig
7.5
HIGH
CVE-2023-48795
all versions
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attacker
5.9
MEDIUM
CVE-2023-3160
all versions
The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move fil
7.8
HIGH
CVE-2022-37348
<= 17.7.1383
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that cou
5.5
MEDIUM
CVE-2022-37347
<= 17.7.1383
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that cou
5.5
MEDIUM
CVE-2022-34893
<= 17.7.1179
Trend Micro Security 2022 (consumer) has a link following vulnerability where an attacker with lower privileges could manipulate a
7.8
HIGH
CVE-2022-29489
<= 1.8.33
Cross-Site Request Forgery (CSRF) vulnerability in Sucuri Security plugin <= 1.8.33 at WordPress leading to Event log entry creati
4.3
MEDIUM
CVE-2022-35234
all versions
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that cou
7.1
HIGH
CVE-2022-30703
all versions
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allow an attac
7.8
HIGH
CVE-2022-30702
all versions
Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerability that cou
5.5
MEDIUM
CVE-2021-37851
>= 6.0 and < 8.0.15009.0
Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the
7.3
HIGH
CVE-2022-27167
>= 6.0 and < 8.0.15009.0
Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" f
7.1
HIGH
CVE-2021-37852
>= 7.0.15008.0 and <= 8.0.15004.0
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to esca
7.8
HIGH
CVE-2020-26941
<= 7.2
A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (delet
5.5
MEDIUM
CVE-2019-14688
all versions
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package
7.0
HIGH
CVE-2018-12636
< 7.0.3
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileg
7.2
HIGH
CVE-2018-7433
<= 6.9.0
The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
7.5
HIGH
CVE-2018-6218
all versions
A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a v
7.0
HIGH
CVE-2005-1239
all versions
Directory traversal vulnerability in the third party tool from Raz-Lee, as used to secure the iSeries AS/400 FTP server, allows re
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin