Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.43% | — | Webtoffee Backup AND Migration | 27/11/2023 | 17/6/2026 | The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks. | |
| Modificada | Media (4.3) | 0.45% | — | Webtoffee Backup AND Migration | 27/11/2023 | 17/6/2026 | The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings. | |
| Modificada | Alta (8.8) | 0.28% | — | Walkeprashant WP ALL Backup | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Prashant Walke WP All Backup plugin <= 2.4.3 versions. | |
| Modificada | Media (5.3) | 0.63% | 💥 PoC | Urbackup Server | 7/11/2023 | 17/6/2026 | UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid. | |
| Modificada | Crítica (9.8) | 7.9% | 💥 Exploit | Vinchin Backup AND Recovery | 27/10/2023 | 17/6/2026 | VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials. | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Vinchin Backup AND Recovery | 27/10/2023 | 17/6/2026 | VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability. | |
| Modificada | Media (4.8) | 0.38% | — | Wpvivid Migration, Backup, Staging | 20/10/2023 | 17/6/2026 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings (the backup path parameter) in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.3) | 0.75% | — | Wpvivid Migration, Backup, Staging | 20/10/2023 | 17/6/2026 | The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets stored in plaintext in the publicly visible plugin source. This could allow unauthenticated attackers to impersonate the WPVivid Google… | |
| Modificada | Media (4.8) | 0.37% | — | Wpvivid Migration, Backup, Staging | 20/10/2023 | 17/6/2026 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image file path parameter in versions up to, and including, 0.9.89 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative… | |
| Modificada | Media (6.5) | 1.5% | — | Wpvivid Migration, Backup, Staging | 20/10/2023 | 17/6/2026 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.9.89. This allows authenticated attackers with administrative privileges to delete the contents of arbitrary directories on the server, which can be a critical issue in a shared… | |
| Modificada | Alta (8.8) | 1.4% | — | Proxmox Backup ServerProxmox Mail GatewayProxmox Virtual Environment | 27/9/2023 | 17/6/2026 | An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component. | |
| Modificada | Media (4.7) | 0.11% | — | Borgbackup Borg | 30/8/2023 | 17/6/2026 | borgbackup is an opensource, deduplicating archiver with compression and authenticated encryption. A flaw in the cryptographic authentication scheme in borgbackup allowed an attacker to fake archives and potentially indirectly cause backup data loss in the repository. The attack requires an attacker to be able to: 1.… | |
| Modificada | Crítica (9.8) | 0.40% | — | Veritas Netbackup Snapshot Manager | 11/8/2023 | 17/6/2026 | A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service. Exploiting this impacts the confidentiality and… | |
| Modificada | Media (4.3) | 0.61% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+6 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (6.5) | 0.69% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+7 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,… | |
| Modificada | Alta (7.2) | 0.62% | — | Veritas Netbackup Appliance | 29/6/2023 | 17/6/2026 | In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH. | |
| Modificada | Alta (7.8) | 0.16% | — | IBM Spectrum Protect Backup-archive Client | 22/6/2023 | 17/6/2026 | IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges due to improper access controls. | |
| Modificada | Media (6.1) | 0.38% | — | WP Backup Solutions Project WP Backup Solutions | 19/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Backup Solutions WP Backup Manager plugin <= 1.13.1 versions. | |
| Modificada | Alta (7.8) | 0.16% | — | Easeus Todo Backup | 12/6/2023 | 17/6/2026 | EaseUS Todo Backup version 20220111.390 - An omission during installation may allow a local attacker to perform privilege escalation. | |
| Modificada | Alta (7.8) | 0.46% | — | Percona Xtrabackup | 7/6/2023 | 17/6/2026 | In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command shell execution of arbitrary commands. | |
| Analizada | Alta (8.1) | 0.53% | — | Netapp Cloud BackupNetapp Ontap Select DeployF5 Nginx API Connectivity ManagerF5 Nginx Instance Manager+1 | 3/5/2023 | 17/6/2026 | NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (8.8) | 5.3% | 💥 Exploit | Acronis Cyber BackupAcronis Cyber Protect | 3/5/2023 | 17/6/2026 | Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545. | |
| Modificada | Alta (7.5) | 3.3% | — | Acronis Cyber BackupAcronis Cyber Protect | 3/5/2023 | 17/6/2026 | Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545. | |
| Modificada | Media (6.1) | 0.44% | — | Veritas Netbackup Appliance Firmware | 10/4/2023 | 17/6/2026 | Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address. | |
| Modificada | Media (6.1) | 0.49% | — | Veritas Netbackup Opscenter | 5/4/2023 | 17/6/2026 | Veritas NetBackUp OpsCenter Version 9.1.0.1 is vulnerable to Reflected Cross-site scripting (XSS). The Web App fails to adequately sanitize special characters. By leveraging this issue, an attacker is able to cause arbitrary HTML and JavaScript code to be executed in a user's browser. |