Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.95%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with unauthenticated access could remotely execute arbitrary commands on a NetBackup Primary server.
ModificadaAlta (7.8)0.20%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with unprivileged local access to a Windows NetBackup Primary server could potentially escalate their privileges.
ModificadaMedia (6.5)0.74%—Veritas Flex ApplianceVeritas Flex ScaleVeritas NetbackupVeritas Netbackup Appliance28/7/202217/6/2026
An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a denial of service attack against a NetBackup Primary server.
ModificadaAlta (7.5)0.56%—Veritas Netbackup27/7/202217/6/2026
In Veritas NetBackup, the NetBackup Client allows arbitrary command execution from any remote host that has access to a valid host-id NetBackup certificate/private key from the same domain. The affects 9.0.x through 9.0.0.1 and 9.1.x through 9.1.0.1.
ModificadaAlta (8.4)0.20%—Veritas Netbackup27/7/202217/6/2026
In Veritas NetBackup, an attacker with unprivileged local access to a NetBackup Client may send specific commands to escalate their privileges. This affects 8.0 through 8.1.2, 8.2, 8.3 through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1.
ModificadaMedia (6.5)0.95%—Veritas Netbackup27/7/202217/6/2026
In Veritas NetBackup OpsCenter, under specific conditions, an authenticated remote attacker may be able to create or modify OpsCenter user accounts. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
ModificadaMedia (4.3)0.79%—Veritas Netbackup27/7/202217/6/2026
In Veritas NetBackup OpsCenter, certain endpoints could allow an unauthenticated remote attacker to gain sensitive information. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
ModificadaCrítica (9.8)0.51%—Veritas Netbackup27/7/202217/6/2026
In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
ModificadaCrítica (9.8)1.2%—Veritas Netbackup27/7/202217/6/2026
In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may compromise the host by exploiting an incorrectly patched vulnerability. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
ModificadaCrítica (9.8)1.8%—Veritas Netbackup27/7/202217/6/2026
In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution through a Java classloader manipulation. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
ModificadaAlta (7.8)0.19%—Veritas Netbackup27/7/202217/6/2026
In Veritas NetBackup OpsCenter, an attacker with local access to a NetBackup OpsCenter server could potentially escalate their privileges. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
ModificadaMedia (5.4)0.44%—Veritas Netbackup27/7/202217/6/2026
In Veritas NetBackup OpsCenter, a DOM XSS attack can occur. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
ModificadaMedia (4.3)0.57%—Jenkins Google Cloud Backup27/7/202217/6/2026
A missing permission check in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers with Overall/Read permission to request a manual backup.
ModificadaAlta (8)0.48%—Jenkins Google Cloud Backup27/7/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers to request a manual backup.
ModificadaAlta (8.8)0.89%—IBM Spectrum Protect Plus Container Backup AND Restore30/6/202217/6/2026
IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, caused by improper disclosure of session information. By…
ModificadaMedia (6.1)1.1%—Androidbubbles Keep Backup Daily13/6/202217/6/2026
The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute…
ModificadaMedia (5.4)0.42%—Deliciousbrains Database Backup8/6/202217/6/2026
The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, which…
ModificadaMedia (6.5)0.96%—Percona Xtrabackup2/6/202217/6/2026
Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include sensitive arguments passed at run time. In addition, when --history is passed at run time, this command line is also written to the PERCONA_SCHEMA.xtrabackup_history table. NOTE: this issue exists…
ModificadaMedia (5.4)0.46%—Veritas Netbackup19/4/202217/6/2026
Veritas NetBackup OpsCenter Analytics 9.1 allows XSS via the NetBackup Master Server Name, Display Name, NetBackup User Name, or NetBackup Password field during a Settings/Configuration Add operation.
ModificadaCrítica (9.8)1.9%—Kaseya Unitrends Backup15/4/202217/6/2026
Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.
ModificadaAlta (7.5)1.5%—Wpvivid Migration, Backup, Staging11/4/202217/6/2026
Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70
ModificadaMedia (6.1)0.80%—Wpvivid Migration, Backup, Staging11/4/202217/6/2026
The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+341/4/202217/6/2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to…
ModificadaAlta (8.8)2.4%—Veeam Backup & Replication17/3/202217/6/2026
Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe
AnalizadaCrítica (9.8)4.1%⚠ Explotación activaVeeam Backup & Replication17/3/202217/6/2026
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).