Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Escanav

First CVE: Jan 25, 2018Active for: 8 yearsTotal CVEs: 28
34.0
VTI Score
Medium

Escanav maintains a focused antivirus and endpoint-protection portfolio, notably the Escan Anti-Virus product line and its associated management console, which serve as critical security controls across a concentrated but prominent user base. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur across its antivirus and administrative components through weakness classes centered on input-handling defects: cross-site scripting, buffer overflows, improper input validation, command injection, and OS command injection. The concentration of critical-severity flaws in endpoint-protection software is particularly significant because such products operate with elevated privileges and sit deep in the host defense chain, making memory-safety and input-validation failures in the antivirus engine or its console a direct path to endpoint compromise. Defenders should treat Escanav advisories as high-priority for any organization deploying these products and ensure timely patching of both the antivirus engine and management infrastructure. Current vulnerability severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Escanav over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 25, 2018
8 years ago
Most Recent CVE
Feb 17, 2025
522 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-31703CRITICAL
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from par
May 17, 20239.041NOYES
CVE-2023-31702HIGH
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to dump entire database and gain windows XP command shell to per
May 17, 20237.236NOYES
CVE-2018-18388CRITICAL
eScan Agent Application (MWAGENT.EXE) 4.0.2.98 in MicroWorld Technologies eScan 14.0 allows remote or local attackers to execute arbitrary commands by sending a carefully crafted p
Dec 20, 20189.830NONO
CVE-2021-26624HIGH
An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions r
Apr 1, 20228.829NONO
CVE-2023-33730CRITICAL
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any a
May 31, 20239.828NONO
CVE-2025-0798HIGH
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the comp
Jan 29, 20258.127NONO
CVE-2024-42919CRITICAL
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
Aug 20, 20249.827NONO
CVE-2023-4383HIGH
A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. This affects an unknown part of the file runasroot. The manipulation le
Aug 16, 20237.824NONO
CVE-2018-6203HIGH
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not va
Jan 25, 20187.823NONO
CVE-2025-1366HIGH
A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. Affected by this issue is the function strcpy of the component VirusPopUp. The ma
Feb 17, 20257.822NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
46%
32%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (50.0%)
Network13 (46.4%)
Unknown0 (0.0%)
Physical1 (3.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (92.9%)
High2 (7.1%)
Unknown0 (0.0%)
User Interaction
None21 (75.0%)
Unknown0 (0.0%)
Required7 (25.0%)
Privileges Required
Low20 (71.4%)
High2 (7.1%)
None6 (21.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
7.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Escanav.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Escanav — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Escanav's Products

View all 3 CNAs →

Top CWEs