Vinchin
Vinchin Backup AND Recovery: vulnerabilidades y CVE
Vinchin Backup AND Recovery tiene 10 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses1
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-60095 | Media (6.9) | 0.74% | — | 9 jul 2026 | Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the… |
| CVE-2024-25228 | Alta (8.8) | 26% | — | 14 mar 2024 | Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php. |
| CVE-2024-22903 | Alta (8.8) | 1.9% | — | 2 feb 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function. |
| CVE-2024-22902 | Crítica (9.8) | 1.1% | — | 2 feb 2024 | Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials. |
| CVE-2024-22901 | Crítica (9.8) | 1.1% | — | 2 feb 2024 | Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials. |
| CVE-2024-22900 | Alta (8.8) | 1.9% | — | 2 feb 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function. |
| CVE-2024-22899 | Alta (8.8) | 2.4% | — | 2 feb 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function. |
| CVE-2023-45499 | Crítica (9.8) | 7.9% | — | 27 oct 2023 | VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials. |
| CVE-2023-45498 | Crítica (9.8) | 20% | — | 27 oct 2023 | VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability. |
| CVE-2022-35866 | Crítica (9.8) | 4.5% | — | 3 ago 2022 | This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw… |