Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.17%—Veritas Aptare IT AnalyticsVeritas Netbackup IT Analytics24/3/202317/6/2026
An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A malicious actor could install rogue Collector executable files (aptare.jar or upgrademanager.zip) on…
ModificadaCrítica (9.8)0.68%—Varta Element Backup FirmwareVarta Element S1 FirmwareVarta Element S2 FirmwareVarta Element S3 Firmware+423/3/202317/6/2026
Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
ModificadaAlta (7.8)0.19%—Veritas Netbackup23/3/202317/6/2026
An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system.
ModificadaAlta (7.1)0.15%—Veritas Netbackup23/3/202317/6/2026
An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.
ModificadaMedia (4.8)0.39%—Jetbackup15/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JetBackup JetBackup – WP Backup, Migrate & Restore plugin <= 1.6.9.0 versions.
ModificadaAlta (7.5)64%💥 ExploitIthemes Backupbuddy13/3/202317/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.
AnalizadaAlta (7.5)81%⚠ Explotación activa💥 PoCVeeam Backup & Replication10/3/202317/6/2026
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.
ModificadaMedia (4.3)0.46%—Xibodevelopment Backupwordpress7/3/202317/6/2026
The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions…
ModificadaAlta (8.8)0.41%—Jetbackup7/3/202317/6/2026
The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.3.9. This is due to missing nonce validation on the backup_guard_get_import_backup() function. This makes it possible for unauthenticated attackers to upload arbitrary files…
ModificadaMedia (4.3)0.64%—Jetbackup7/3/202317/6/2026
The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to sensitive information disclosure in versions up to, and including, 1.4.0 due to a lack of proper capability checking on the backup_guard_get_manual_modal function called via an AJAX action. This makes it possible for subscriber-level…
ModificadaMedia (5.4)0.48%—Jetbackup7/3/202317/6/2026
The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes in versions up to, and including 1.4.1 due to a lack of proper capability checking on the backup_guard_cloud_dropbox, backup_guard_cloud_gdrive, and backup_guard_cloud_oneDrive functions. This makes…
ModificadaMedia (6.1)0.86%💥 ExploitIthemes Backupbuddy21/2/202317/6/2026
The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting
ModificadaCrítica (9.8)0.77%—Veeam Backup FOR Google Cloud5/12/202217/6/2026
Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.
ModificadaCrítica (9.8)1.4%—Veritas Access ApplianceVeritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.
ModificadaAlta (8.8)1.5%—Veritas Access ApplianceVeritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal.
ModificadaAlta (8.8)0.73%—Veritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands.
ModificadaAlta (8.8)0.61%—Veritas Access ApplianceVeritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.
ModificadaAlta (8.8)0.61%—Veritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands.
ModificadaAlta (8.8)0.80%—Veritas Netbackup17/11/202217/6/2026
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.
ModificadaAlta (7.1)0.21%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbx_exchange registration code.
ModificadaCrítica (9.8)0.61%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.
ModificadaMedia (5.5)0.19%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbx_exchange during registration and cause a NULL pointer exception, effectively crashing the pbx_exchange process.
ModificadaAlta (7.5)0.67%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a Path traversal attack through the DiscoveryService service.
ModificadaCrítica (9.8)0.60%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting idm, nbars, and SLP manager code.
ModificadaCrítica (9.8)0.60%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a second-order SQL Injection attack affecting the NBFSMCLIENT service by leveraging CVE-2022-42302.