ESET, spol. s r.o.

First CVE: Nov 8, 2021Active for: 5 years
35
CVEs Published
More CVEs Published than 50% of tracked CNAs
5.8
Avg CVEs / Year
More Avg CVEs / Year than 36% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked CNAs
11.4%
In CISA KEV
Higher KEV Rate than 98% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by ESET, spol. s r.o. as a CNA, 37.1% affect products that ESET, spol. s r.o. develops as a vendor.

37.1%
62.9%
Self-reported: 13Third-party: 22

Of all the CVEs published that affect products developed by ESET, spol. s r.o., 28.9% are self-published by ESET, spol. s r.o. as a CNA.

28.9%
71.1%
Self-published: 13Published by other CNAs: 32

Trends Over Time

The number and severity of CVEs published by ESET, spol. s r.o. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2021
4 years ago
Most Recent CVE
Jul 16, 2026
8 days ago

Top CVEs

All CVEs published by ESET, spol. s r.o. as a CNA, regardless of affected vendor or product.

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was ex
Aug 8, 20258.896YESNO
Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_
Oct 18, 20235.489YESNO
An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remot
Nov 15, 20246.167YESNO
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arb
Aug 15, 20247.865YESNO
A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authentication in an IPC channel.
Jul 16, 20268.537NONO
Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system
Jul 16, 20266.732NONO
Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL.
Jan 30, 20268.430NONO
DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicious dynamic-link library and execute its code.
Apr 7, 20258.428NONO
The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without hav
Sep 27, 20248.528NONO
The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allows an attacker who successfully recovered the private key to
Mar 27, 20259.527NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA35 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local25 (71.4%)
Network9 (25.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (97.1%)
High1 (2.9%)
Unknown0 (0.0%)
User Interaction
None24 (68.6%)
Unknown0 (0.0%)
Required8 (22.9%)
Privileges Required
Low20 (57.1%)
High4 (11.4%)
None11 (31.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (35 CVEs).

CISA KEV
4 CVEs
11.4% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by ESET, spol. s r.o. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by ESET, spol. s r.o. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs