Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.62%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting the NBFSMCLIENT service.
ModificadaAlta (8.8)0.65%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) injection attack through the nbars process.
ModificadaMedia (6.5)0.70%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server nbars process can be crashed resulting in a denial of service. (Note: the watchdog service will automatically restart the process.)
ModificadaAlta (7.5)0.73%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a denial of service attack through the DiscoveryService service.
ModificadaAlta (8.8)0.43%—Backup Scheduler Project Backup Scheduler23/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability Backup Scheduler plugin <= 1.5.13 at WordPress.
ModificadaAlta (7.2)22%—Ahsay Cloud Backup Suite21/9/202217/6/2026
Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote…
ModificadaMedia (4.9)25%💥 ExploitWpvivid Migration, Backup, Staging16/9/202217/6/2026
The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it to read the content of a file, allowing high privilege users to read any file from the web server via a Traversal attack
ModificadaMedia (4.9)0.52%—Haystacksoftware ARQ Backup9/9/202217/6/2026
Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attackers with administrative privileges to recover cleartext passwords.
ModificadaAlta (7.2)1.8%—Wpvivid Migration, Backup, Staging6/9/202217/6/2026
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via the 'path' parameter in versions up to, and including 0.9.74. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize…
ModificadaMedia (4.8)0.51%—Wpseeds WP Database Backup5/9/202217/6/2026
The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaCrítica (9.8)4.5%—Vinchin Backup AND Recovery3/8/202217/6/2026
This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MySQL server. The server uses a hard-coded password for the…
ModificadaMedia (6.5)0.69%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.
ModificadaMedia (6.5)0.69%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). Under certain conditions, an attacker with authenticated access to a NetBackup Client could remotely read files on a NetBackup Primary server.
ModificadaMedia (6.5)0.66%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a stack-based buffer overflow on the NetBackup Primary…
ModificadaAlta (8.8)0.70%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger impacts that include arbitrary file read, Server-Side Request…
ModificadaMedia (6.5)0.60%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with access to a NetBackup Client could remotely gather information about any host known to a NetBackup Primary server.
ModificadaMedia (4.3)0.51%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily create directories on a NetBackup Primary server.
ModificadaMedia (6.5)0.61%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily read files from a NetBackup Primary server.
ModificadaAlta (8.8)1.0%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server.
ModificadaAlta (8.8)1.0%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server (in specific…
ModificadaMedia (6.5)0.66%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily write content to a partially controlled path on a NetBackup…
ModificadaMedia (6.5)0.66%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely write arbitrary files to arbitrary locations from any Client to any…
ModificadaAlta (8.8)1.0%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on a NetBackup Primary server.
ModificadaAlta (8.8)0.89%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup OpsCenter server, NetBackup Primary server, or NetBackup Media server could remotely…
ModificadaMedia (6.5)0.63%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could arbitrarily write files to a NetBackup Primary server.
Orbitaley — Vulnerabilidades