Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

42 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)12%💥 ExploitKaseya Unitrends Backup7/8/201717/6/2026
It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existing low-privilege credentials could then execute arbitrary commands…
ModificadaCrítica (9.8)78%💥 ExploitKaseya Unitrends Backup7/8/201717/6/2026
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker could use this flaw to bypass authentication and execute arbitrary commands with root privilege on the target system.
ModificadaCrítica (9.8)68%💥 ExploitKaseya Unitrends Backup7/8/201717/6/2026
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypassed. A remote attacker could use this issue to execute arbitrary commands with root privilege on the target system.
ModificadaAlta (8.8)4.3%—Unitrends Enterprise Backup20/4/201717/6/2026
An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /api/restore/download-files endpoint, related to the downloadFiles function in api/includes/restore.php.
ModificadaMedia (5.5)4.3%—Unitrends Enterprise Backup20/4/201717/6/2026
An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File…
ModificadaAlta (8.8)2.7%—Unitrends Enterprise Backup12/4/201717/6/2026
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.
ModificadaAlta (8.8)4.3%—Unitrends Enterprise Backup12/4/201717/6/2026
An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file on disk with a user-controlled extension, contents, and path,…
ModificadaCrítica (9.8)6.2%—Unitrends Enterprise Backup12/4/201717/6/2026
An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sent to a popen function. This allows for remote code execution by sending a specially crafted user variable.
ModificadaCrítica (9.8)4.4%—Unitrends Enterprise Backup12/4/201717/6/2026
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.
ModificadaAlta (7.5)3.3%💥 ExploitUnitrends Enterprise Backup2/5/201417/6/2026
recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to a certain string.
ModificadaAlta (10)7.0%💥 ExploitUnitrends Enterprise Backup28/4/201417/6/2026
Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to recoveryconsole/bpl/snmpd.php.
ModificadaMedia (4.3)0.87%—Webtrends LOG Analyzer5/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
ModificadaMedia (4.3)4.8%💥 ExploitWebtrends Reporting Center31/12/200416/6/2026
viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.
ModificadaAlta (7.5)11%💥 ExploitWebtrends Reporting Center18/6/200216/6/2026
Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ directory.
ModificadaMedia (5)1.5%—Webtrends Reporting Center18/6/200216/6/2026
WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks the pathname in an error message.
ModificadaMedia (5)3.1%💥 ExploitWebtrends Enterprise Reporting ServerWebtrends Enterprise Reporting Server NT20/9/200116/6/2026
WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).
ModificadaBaja (2.1)0.40%—Webtrends Enterprise SuiteWebtrends FOR FirewallsWebtrends LOG AnalyzerWebtrends Professional Suite+129/6/199916/6/2026
WebTrends software stores account names and passwords in a file which does not have restricted access permissions.
Orbitaley — Vulnerabilidades