Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.53% | — | Revmakx Backup AND Staging BY WP Time CapsuleAI | 1/8/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.20. | |
| Modificada | Media (5.5) | 0.31% | — | Mommyheather Advanced Backups | 9/7/2024 | 17/6/2026 | Mommy Heather Advanced Backups up to v3.5.3 allows attackers to write arbitrary files via restoring a crafted back up. | |
| Aplazada | Alta (7.5) | 0.47% | — | Msp360 Backup AgentAI | 2/7/2024 | 17/6/2026 | An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup due to enginesettings.list being encrypted with a hard coded key. | |
| Aplazada | Media (5.4) | 0.37% | — | Webtoffee Wordpress Backup AND MigrationAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.3. | |
| Modificada | Media (6.1) | 0.26% | — | Wpvivid Backup FOR Mainwp | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpvividplugins WPvivid Backup for MainWP wpvivid-backup-mainwp allows Reflected XSS.This issue affects WPvivid Backup for MainWP: from n/a through <= 0.9.32. | |
| Analizada | Alta (7.1) | 0.28% | — | Phpmybackuppro | 28/5/2024 | 17/6/2026 | A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/backup.php, 'comments' and 'db' parameters. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim to retrieve their session… | |
| Analizada | Alta (7.1) | 0.25% | — | Phpmybackuppro | 28/5/2024 | 17/6/2026 | A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/get_file.php, 'view' parameter. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim to retrieve their session details. | |
| Analizada | Media (6.1) | 0.28% | — | Phpmybackuppro | 28/5/2024 | 17/6/2026 | A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/scheduled.php, all parameters. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim to retrieve their session details. | |
| Analizada | Baja (2.7) | 0.53% | — | Veeam Backup & Replication | 22/5/2024 | 17/6/2026 | Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs. | |
| Analizada | Alta (7.2) | 0.92% | — | Veeam Backup & Replication | 22/5/2024 | 17/6/2026 | Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account. | |
| Analizada | Alta (8.8) | 0.81% | — | Veeam Backup & Replication | 22/5/2024 | 17/6/2026 | Veeam Backup Enterprise Manager allows account takeover via NTLM relay. | |
| Analizada | Crítica (9.8) | 38% | 💥 PoC | Veeam Backup & Replication | 22/5/2024 | 17/6/2026 | Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. | |
| Analizada | Alta (8.8) | 0.71% | — | Wpvivid Migration, Backup, Staging | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a through 0.9.90. | |
| Aplazada | Media (6.8) | 0.37% | — | Veritas NetbackupAIVeritas Netbackup ApplianceAI | 3/5/2024 | 17/6/2026 | A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Appliance before 5.4. By design, only the cloud administrator should be able to disable the retention lock of Governance mode images. This vulnerability allowed a NetBackup administrator to modify the… | |
| Aplazada | Media (4.3) | 0.49% | — | Wordpress Backup AND MigrationAI | 2/5/2024 | 17/6/2026 | The WordPress Backup & Migration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wp_mgdp_populate_popup function in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with subscriber access or above, to invoke this… | |
| Aplazada | Baja (2.7) | 0.65% | — | Xibodevelopment BackupwordpressAI | 27/4/2024 | 17/6/2026 | The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse directories outside of the context in which the… | |
| Analizada | Alta (7.8) | 0.16% | — | Veritas Backup Exec | 26/4/2024 | 17/6/2026 | An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path. | |
| Analizada | Alta (7.1) | 0.17% | — | Veritas Netbackup | 26/4/2024 | 17/6/2026 | An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files. | |
| Analizada | Alta (7.1) | 0.17% | — | Veritas Backup Exec | 26/4/2024 | 17/6/2026 | An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files. | |
| Aplazada | Media (5.3) | 0.44% | — | Inisev Backup MigrationAI | 18/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migration: from n/a through 1.4.3. | |
| Analizada | Media (6.5) | 0.65% | — | Everestthemes Everest Backup | 15/4/2024 | 17/6/2026 | The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup) | |
| Modificada | Alta (7.2) | 42% | — | Wpvivid Migration, Backup, Staging | 12/4/2024 | 17/6/2026 | WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action. This is due to the plugin not providing sufficient path validation on the tree_node[node][id]… | |
| Modificada | Alta (7.5) | 0.48% | — | Webtoffee Backup AND Migration | 10/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migration: from n/a through 1.4.7. | |
| Analizada | Media (5.3) | 0.56% | — | Wpbackitup Backup AND Restore Wordpress | 26/3/2024 | 17/6/2026 | The Backup and Restore WordPress WordPress plugin through 1.45 does not protect some log files containing sensitive information such as site configuration etc, allowing unauthenticated users to access such data | |
| Analizada | Media (4.7) | 0.55% | — | Backupbolt Backup Bolt | 18/3/2024 | 17/6/2026 | The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may contain information like system errors which could contain sensitive information. |