Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.1) | — | — | Veeam Backup AND ReplicationAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup & Replication allows a Backup Viewer to modify the Enterprise Manager master key and stored antivirus update credentials. | |
| Recibida | Alta (8.3) | — | — | Veeam Backup AND ReplicationAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbitrary files on the service provider host. | |
| Recibida | Crítica (9.4) | — | — | Veeam Backup AND ReplicationAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server. | |
| Recibida | Media (4.8) | — | — | Veeam Backup Enterprise ManagerAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script in the browser of a portal user who opens a crafted link. | |
| Aplazada | Alta (7.5) | 0.32% | — | Norvis BackupAI | 6/10/2026 | 6/10/2026 | Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions. | |
| Aplazada | Alta (7.5) | 0.30% | — | WXD Backup LiteAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions. | |
| Aplazada | Crítica (10) | 0.31% | — | Backupsheep Wordpress Backup PluginAI | 1/10/2026 | 1/10/2026 | The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files… | |
| Aplazada | Alta (7.5) | 0.30% | — | BackupeaseAI | 30/9/2026 | 30/9/2026 | Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions. | |
| Aplazada | Alta (7.5) | 0.30% | — | Stifli Backup ToolsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions. | |
| Aplazada | Alta (7.5) | 0.29% | — | Wordpress Backup MigrationAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. | |
| Aplazada | Media (4.8) | 0.10% | — | Veritas Netbackup Flex OSAI | 18/9/2026 | 18/9/2026 | An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitation could expose sensitive system configuration and credential material stored on the… | |
| Aplazada | Crítica (9.4) | 0.34% | — | Veritas Netbackup FlexAI | 18/9/2026 | 18/9/2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Successful exploitation grants the attacker an unrestricted root shell with full… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Veritas Netbackup FlexAI | 18/9/2026 | 18/9/2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permissions. Successful exploitation grants the attacker unrestricted control over the Flex… | |
| Aplazada | Alta (7.2) | 0.46% | — | Servmask All-in-one WP Migration AND BackupAI | 18/9/2026 | 18/9/2026 | The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import an arbitrary site archive and gain… | |
| Analizada | Alta (7.8) | 0.23% | ⚠ Explotación activa | Acronis Backup | 17/9/2026 | 18/9/2026 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238. | |
| Aplazada | Crítica (9.6) | 0.25% | — | Webtotem BackupsAI | 12/9/2026 | 23/9/2026 | The WebTotem Backups WordPress plugin before 1.1.0 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to… | |
| Pendiente de análisis | Crítica (9.9) | 0.65% | — | Plesk Backup ManagerAI | 10/9/2026 | 10/9/2026 | Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. | |
| Aplazada | Alta (7.5) | 0.42% | — | Zhbackup Backup Restore MigrationAI | 10/9/2026 | 10/9/2026 | Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions. | |
| Pendiente de análisis | Alta (8) | 1.7% | — | Spatie Laravel-backup-restoreAISpatie Laravel-backupAI | 4/9/2026 | 10/9/2026 | laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4. | |
| Aplazada | Media (5.5) | 0.34% | — | Wpvivid Backup Migration StagingAI | 4/9/2026 | 8/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root. | |
| Aplazada | Media (5.5) | 0.38% | — | Wpvivid Backup Migration StagingAI | 4/9/2026 | 8/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files. | |
| Pendiente de análisis | Alta (7.1) | 0.38% | — | Jenkins ThinbackupAI | 2/9/2026 | 3/9/2026 | Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system in backups. | |
| Aplazada | Alta (7.1) | 0.19% | — | JetbackupAI | 2/9/2026 | 3/9/2026 | The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site. | |
| Aplazada | Alta (8.7) | 0.52% | — | Androidbubbles Keep Backup DailyAI | 31/8/2026 | 8/9/2026 | Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` parameter without authentication. Attackers can predict the partially predictable… | |
| Aplazada | Media (6.6) | 0.26% | — | Wpvivid Backup Migration StagingAI | 30/8/2026 | 3/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution. |