Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.9)0.91%—Softaculous BackuplyAI16/3/202417/6/2026
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.7 via the backup_name parameter in the backuply_download_backup function. This makes it possible for attackers to have an account with only activate_plugins capability…
ModificadaAlta (8.8)26%—Vinchin Backup AND Recovery14/3/202417/6/2026
Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.
ModificadaMedia (6.1)0.61%—Wpvivid Backup FOR Mainwp13/3/202417/6/2026
The WPvivid Backup for MainWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 0.9.32 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AnalizadaCrítica (9.8)0.99%—Veritas NetbackupVeritas Netbackup Appliance7/3/202417/6/2026
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
ModificadaCrítica (9.1)0.83%—Wpvivid Migration, Backup, Staging29/2/202417/6/2026
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_restore_progress() and restore() functions in all versions up to, and including, 0.9.68. This makes it possible for unauthenticated attackers to exploit a SQL injection…
AnalizadaCrítica (9.1)1.1%—Wpvivid Migration, Backup, Staging29/2/202417/6/2026
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers…
AnalizadaAlta (7.5)1.9%💥 ExploitJetbackup27/2/202417/6/2026
The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.
AplazadaAlta (7.5)0.52%—UI Unifi Access PointsAIUI Unifi SwitchesAIUI Unifi LTE BackupAIUI Unifi ExpressAI20/2/202417/6/2026
A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected Products: UniFi Access Points UniFi Switches UniFi LTE Backup UniFi Express (Only Mesh Mode, Router mode is not affected) Mitigation: Update UniFi…
ModificadaAlta (7.5)0.96%—Softaculous Backuply9/2/202417/6/2026
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to make excessive requests that result in…
ModificadaMedia (5.3)0.61%—Wpvivid Migration, Backup, Staging5/2/202417/6/2026
The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in versions up to, and including, 0.9.94. This makes it possible for unauthenticated attackers to invoke these functions and obtain full file paths if…
ModificadaAlta (8.8)1.9%—Vinchin Backup AND Recovery2/2/20249/7/2026
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.
ModificadaCrítica (9.8)1.1%—Vinchin Backup AND Recovery2/2/20249/7/2026
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
ModificadaCrítica (9.8)1.1%—Vinchin Backup AND Recovery2/2/20249/7/2026
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
ModificadaAlta (8.8)1.9%—Vinchin Backup AND Recovery2/2/20249/7/2026
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.
ModificadaAlta (8.8)2.4%💥 PoCVinchin Backup AND Recovery2/2/20249/7/2026
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.
ModificadaMedia (4.9)0.76%—Softaculous Backuply27/1/202417/6/2026
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.3 via the node_id parameter in the backuply_get_jstree function. This makes it possible for attackers with administrator privileges or higher to read the contents of…
ModificadaAlta (7.5)2.1%💥 ExploitBackupbliss Backup Migration11/1/202417/6/2026
The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated attackers to download back-up files which…
ModificadaAlta (7.5)2.0%💥 ExploitBackupbliss Clone8/1/202417/6/2026
The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.
ModificadaAlta (7.5)0.69%—Backupbliss Backup Migration1/1/202417/6/2026
The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.
ModificadaAlta (7.5)0.45%—Everestthemes Everest Backup31/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Everestthemes Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin.This issue affects Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin: from n/a through 2.1.9.
ModificadaCrítica (9.8)0.93%—Outdoorbits Little Backup BOX30/12/202317/6/2026
outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code because the PHP extract function is used for untrusted input.
ModificadaAlta (7.2)31%—Backupbliss Backup Migration23/12/202317/6/2026
The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands on the host operating system.
ModificadaCrítica (9.8)1.4%💥 PoCBackupbliss Backup Migration23/12/202317/6/2026
The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for unauthenticated attackers to delete arbitrary files,…
ModificadaCrítica (9.8)6.4%—Backupbliss Backup Migration23/12/202317/6/2026
The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. NOTE: Successful exploitation of this vulnerability…
ModificadaCrítica (9.8)98%💥 ExploitBackupbliss Backup Migration15/12/202317/6/2026
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This…