Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.17% | — | Veritas Aptare IT AnalyticsVeritas Netbackup IT Analytics | 24/3/2023 | 17/6/2026 | An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A malicious actor could install rogue Collector executable files (aptare.jar or upgrademanager.zip) on… | |
| Modificada | Crítica (9.8) | 0.68% | — | Varta Element Backup FirmwareVarta Element S1 FirmwareVarta Element S2 FirmwareVarta Element S3 Firmware+4 | 23/3/2023 | 17/6/2026 | Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network. | |
| Modificada | Alta (7.8) | 0.19% | — | Veritas Netbackup | 23/3/2023 | 17/6/2026 | An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system. | |
| Modificada | Alta (7.1) | 0.15% | — | Veritas Netbackup | 23/3/2023 | 17/6/2026 | An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files. | |
| Modificada | Media (4.8) | 0.39% | — | Jetbackup | 15/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JetBackup JetBackup – WP Backup, Migrate & Restore plugin <= 1.6.9.0 versions. | |
| Modificada | Alta (7.5) | 64% | 💥 Exploit | Ithemes Backupbuddy | 13/3/2023 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1. | |
| Analizada | Alta (7.5) | 81% | ⚠ Explotación activa💥 PoC | Veeam Backup & Replication | 10/3/2023 | 17/6/2026 | Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts. | |
| Modificada | Media (4.3) | 0.46% | — | Xibodevelopment Backupwordpress | 7/3/2023 | 17/6/2026 | The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions… | |
| Modificada | Alta (8.8) | 0.41% | — | Jetbackup | 7/3/2023 | 17/6/2026 | The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.3.9. This is due to missing nonce validation on the backup_guard_get_import_backup() function. This makes it possible for unauthenticated attackers to upload arbitrary files… | |
| Modificada | Media (4.3) | 0.64% | — | Jetbackup | 7/3/2023 | 17/6/2026 | The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including, 1.4.0 due to a lack of proper capability checking on the backup_guard_get_manual_modal function called via an AJAX action. This makes it possible for subscriber-level… | |
| Modificada | Media (5.4) | 0.48% | — | Jetbackup | 7/3/2023 | 17/6/2026 | The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes in versions up to, and including 1.4.1 due to a lack of proper capability checking on the backup_guard_cloud_dropbox, backup_guard_cloud_gdrive, and backup_guard_cloud_oneDrive functions. This makes… | |
| Modificada | Media (6.1) | 0.86% | 💥 Exploit | Ithemes Backupbuddy | 21/2/2023 | 17/6/2026 | The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 0.77% | — | Veeam Backup FOR Google Cloud | 5/12/2022 | 17/6/2026 | Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms. | |
| Modificada | Crítica (9.8) | 1.4% | — | Veritas Access ApplianceVeritas Netbackup Flex Scale Appliance | 4/12/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal. | |
| Modificada | Alta (8.8) | 1.5% | — | Veritas Access ApplianceVeritas Netbackup Flex Scale Appliance | 4/12/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal. | |
| Modificada | Alta (8.8) | 0.73% | — | Veritas Netbackup Flex Scale Appliance | 4/12/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands. | |
| Modificada | Alta (8.8) | 0.61% | — | Veritas Access ApplianceVeritas Netbackup Flex Scale Appliance | 4/12/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges. | |
| Modificada | Alta (8.8) | 0.61% | — | Veritas Netbackup Flex Scale Appliance | 4/12/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands. | |
| Modificada | Alta (8.8) | 0.80% | — | Veritas Netbackup | 17/11/2022 | 17/6/2026 | The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root. | |
| Modificada | Alta (7.1) | 0.21% | — | Veritas Netbackup | 3/10/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbx_exchange registration code. | |
| Modificada | Crítica (9.8) | 0.61% | — | Veritas Netbackup | 3/10/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service. | |
| Modificada | Media (5.5) | 0.19% | — | Veritas Netbackup | 3/10/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbx_exchange during registration and cause a NULL pointer exception, effectively crashing the pbx_exchange process. | |
| Modificada | Alta (7.5) | 0.67% | — | Veritas Netbackup | 3/10/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a Path traversal attack through the DiscoveryService service. | |
| Modificada | Crítica (9.8) | 0.60% | — | Veritas Netbackup | 3/10/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting idm, nbars, and SLP manager code. | |
| Modificada | Crítica (9.8) | 0.60% | — | Veritas Netbackup | 3/10/2022 | 17/6/2026 | An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a second-order SQL Injection attack affecting the NBFSMCLIENT service by leveraging CVE-2022-42302. |