Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
82 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 24% | — | Veeam Backup & Replication | 19/6/2025 | 17/6/2026 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user | |
| Analizada | Alta (8.8) | 24% | — | Veeam Backup & Replication | 20/3/2025 | 17/6/2026 | A vulnerability allowing remote code execution (RCE) for domain users. | |
| Aplazada | Crítica (9) | 0.64% | — | Veeam UpdaterAI | 5/2/2025 | 17/6/2026 | A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate. | |
| Analizada | Alta (7.2) | 0.34% | — | Veeam Backup | 14/1/2025 | 17/6/2026 | Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Alta (7) | 0.18% | — | Veeam Agent FOR Windows | 4/12/2024 | 17/6/2026 | DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to… | |
| Analizada | Media (6.5) | 0.25% | — | Veeam Service Provider Console | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources. | |
| Analizada | Media (4.3) | 0.36% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial target and potentially leading to broader… | |
| Analizada | Media (6.5) | 0.41% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a remote management interface. This can be achieved using a session object that allows for credential enumeration and exploitation, leading to the leak of… | |
| Analizada | Alta (8.8) | 0.39% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate used for authentication on a specific port. This can result in unauthorized access, enabling the… | |
| Analizada | Alta (8.1) | 15% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service account privileges. The vulnerability is… | |
| Analizada | Alta (8.1) | 0.34% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially leading to Denial of Service (DoS) and… | |
| Analizada | Alta (8.8) | 0.50% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to system-level access. This allows the attacker to upload files to the server with elevated privileges. The vulnerability exists because remote… | |
| Analizada | Media (6.5) | 0.28% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an external protocol, ultimately retrieving the credentials using a malicious setup on the attacker's side. This exposes sensitive data, which could… | |
| Analizada | Alta (8.8) | 0.76% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The… | |
| Analizada | Alta (7.7) | 0.61% | — | Veeam Backup & Replication | 7/11/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability. | |
| Analizada | Alta (8.8) | 1.3% | — | Veeam ONE | 7/9/2024 | 17/6/2026 | A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed. | |
| Analizada | Alta (8.8) | 0.47% | — | Veeam ONE | 7/9/2024 | 17/6/2026 | An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely. | |
| Analizada | Media (5.3) | 0.28% | — | Veeam ONE | 7/9/2024 | 17/6/2026 | An incorrect permission assignment vulnerability allows an attacker to modify product configuration files. | |
| Analizada | Media (6.5) | 0.30% | — | Veeam ONE | 7/9/2024 | 17/6/2026 | An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials. | |
| Modificada | Media (5.4) | 0.41% | — | Veeam ONE | 7/9/2024 | 17/6/2026 | A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection. | |
| Analizada | Alta (8) | 0.54% | — | Veeam ONE | 7/9/2024 | 17/6/2026 | A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data collected from Veeam Backup & Replication. | |
| Analizada | Alta (8.3) | 0.36% | — | Veeam Backup & Replication | 7/9/2024 | 17/6/2026 | An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations. | |
| Analizada | Alta (7.8) | 0.32% | — | Veeam Backup & Replication | 7/9/2024 | 17/6/2026 | A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA. | |
| Analizada | Alta (7.8) | 0.29% | — | Veeam Backup & Replication | 7/9/2024 | 17/6/2026 | A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE). | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa💥 Exploit | Veeam Backup & Replication | 7/9/2024 | 17/6/2026 | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). |