Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.7)0.61%—Veeam Backup & Replication7/11/202417/6/2026
A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.
AnalizadaAlta (7.5)0.46%—Everestthemes Everest Backup6/11/202417/6/2026
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.13 via the exposed process stats file during the backup process. This makes it possible for unauthenticated attackers to obtain…
AnalizadaAlta (8.8)0.45%—Backupbliss Clone1/11/202417/6/2026
Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.
AnalizadaAlta (8.8)0.45%—Backupbliss Clone1/11/202417/6/2026
Missing Authorization vulnerability in Migrate Clone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clone: from n/a through 2.4.5.
AplazadaMedia (5.3)0.38%—Wpbackitup Backup AND RestoreAI1/11/202417/6/2026
Missing Authorization vulnerability in WPBackItUp Backup and Restore WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Backup and Restore WordPress: from n/a through 1.50.
AplazadaMedia (5.4)0.32%—Wpbackitup Backup AND RestoreAI1/11/202417/6/2026
Access Control vulnerability in WPBackItUp Backup and Restore WordPress allows . This issue affects Backup and Restore WordPress: from n/a through 1.50.
AplazadaAlta (7.5)0.42%—Fahadmahmood Keep Backup DailyAI17/10/202417/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Fahad Mahmood Keep Backup Daily keep-backup-daily allows Retrieve Embedded Sensitive Data.This issue affects Keep Backup Daily: from n/a through <= 2.1.3.
AnalizadaAlta (8.8)1.2%💥 PoCWpvivid Migration, Backup, Staging16/10/202417/6/2026
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivid_upload_import_files and wpvivid_upload_files AJAX actions that allows low-level authenticated attackers to upload zip files that can be subsequently extracted. This…
AnalizadaMedia (6.5)0.55%—Wpvivid Migration, Backup, Staging16/10/202417/6/2026
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their…
AplazadaAlta (8.5)0.49%—Revmakx Backup AND Staging BY WP Time CapsuleAI11/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows SQL Injection.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.21.
AnalizadaAlta (7.5)0.58%—Wpvivid Migration, Backup, Staging2/10/202417/6/2026
The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers to leak sensitive information about said backups.
AnalizadaMedia (5.3)0.08%—Synology Active Backup FOR Business Agent26/9/202417/6/2026
Missing encryption of sensitive data vulnerability in login component in Synology Active Backup for Business Agent before 2.7.0-3221 allows adjacent man-in-the-middle attackers to obtain user credential via unspecified vectors.
AnalizadaMedia (5.5)0.18%—Synology Active Backup FOR Business Agent26/9/202417/6/2026
Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.
AnalizadaMedia (5)0.08%—Synology Active Backup FOR Business Agent26/9/202417/6/2026
Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential via unspecified vectors.
AnalizadaBaja (3.3)0.16%—Synology Active Backup FOR Business Agent26/9/202417/6/2026
Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecified vectors. The backup functionality will continue to operate and will not be affected by the logout.
AplazadaCrítica (9.9)0.48%—Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAIAcronis Backup Plugin FOR DirectadminAI17/9/202417/6/2026
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147.
AnalizadaAlta (7.2)17%—Softaculous Backuply14/9/202417/6/2026
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
AnalizadaMedia (4.3)0.20%—Snapshot Backup Project Snapshot Backup9/9/202417/6/2026
The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
AnalizadaAlta (8.3)0.36%—Veeam Backup & Replication7/9/202417/6/2026
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.
AnalizadaAlta (7.8)0.32%—Veeam Backup & Replication7/9/202417/6/2026
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
AnalizadaAlta (7.8)0.29%—Veeam Backup & Replication7/9/202417/6/2026
A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).
AnalizadaCrítica (9.8)90%⚠ Explotación activa💥 ExploitVeeam Backup & Replication7/9/202417/6/2026
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
AnalizadaAlta (8.8)1.1%—Veeam Backup & Replication7/9/202417/6/2026
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup &…
AnalizadaAlta (8.1)0.83%—Veeam Backup & Replication7/9/202417/6/2026
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
AnalizadaMedia (4.3)0.18%—Wpbackitup Backup AND Restore Wordpress26/8/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.