ESET, spol. s r.o.
First CVE: Nov 8, 2021Active for: 5 years
35
CVEs Published
More CVEs Published than 50% of tracked CNAs
5.8
Avg CVEs / Year
More Avg CVEs / Year than 36% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked CNAs
11.4%
In CISA KEV
Higher KEV Rate than 98% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by ESET, spol. s r.o. as a CNA, 37.1% affect products that ESET, spol. s r.o. develops as a vendor.
37.1%
62.9%
Self-reported: 13Third-party: 22
Of all the CVEs published that affect products developed by ESET, spol. s r.o., 28.9% are self-published by ESET, spol. s r.o. as a CNA.
28.9%
71.1%
Self-published: 13Published by other CNAs: 32
Trends Over Time
The number and severity of CVEs published by ESET, spol. s r.o. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 8, 2021
4 years ago
Most Recent CVE
Jul 16, 2026
8 days ago
Top CVEs
All CVEs published by ESET, spol. s r.o. as a CNA, regardless of affected vendor or product.
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8088HIGH A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was ex | Aug 8, 2025 | 8.8 | 96 | YES | NO |
CVE-2023-5631MEDIUM Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_ | Oct 18, 2023 | 5.4 | 89 | YES | NO |
CVE-2024-11182MEDIUM An XSS issue was discovered in
MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message
with
JavaScript in an img tag. This could
allow a remot | Nov 15, 2024 | 6.1 | 67 | YES | NO |
CVE-2024-7262HIGH Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arb | Aug 15, 2024 | 7.8 | 65 | YES | NO |
CVE-2026-6423HIGH A local privilege escalation vulnerability in ESET Inspect Connector.
The vulnerability was caused by improper authentication in an IPC channel. | Jul 16, 2026 | 8.5 | 37 | NO | NO |
CVE-2026-6424MEDIUM Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system | Jul 16, 2026 | 6.7 | 32 | NO | NO |
CVE-2025-13176HIGH Planting a custom configuration file
in
ESET Inspect Connector allow load a malicious DLL. | Jan 30, 2026 | 8.4 | 30 | NO | NO |
CVE-2024-11859HIGH DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicious dynamic-link library and execute its code. | Apr 7, 2025 | 8.4 | 28 | NO | NO |
CVE-2024-7400HIGH The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without hav | Sep 27, 2024 | 8.5 | 28 | NO | NO |
CVE-2025-2516CRITICAL The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allows an attacker who successfully recovered the private key to | Mar 27, 2025 | 9.5 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA35 CVEs
43%
51%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local25 (71.4%)
Network9 (25.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (97.1%)
High1 (2.9%)
Unknown0 (0.0%)
User Interaction
None24 (68.6%)
Unknown0 (0.0%)
Required8 (22.9%)
Privileges Required
Low20 (57.1%)
High4 (11.4%)
None11 (31.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (35 CVEs).
CISA KEV
4 CVEs
11.4% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by ESET, spol. s r.o. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by ESET, spol. s r.o. as a CNA — matched by CVE ID, not by organization name.