Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1213 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.16%—Aomei BackupperAI21/6/202622/6/2026
A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized.…
AplazadaAlta (7.5)0.42%—Backupbliss Backup MigrationAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.
AplazadaAlta (8.7)0.60%—Simple-backupAI15/6/202617/6/2026
WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrary files and download sensitive files by manipulating the delete_backup_file and download_backup_file parameters in tools.php. Attackers can exploit insufficient input validation using directory…
AplazadaMedia (6.6)0.78%—Backupbliss Backup MigrationAI6/6/202623/7/2026
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP…
AplazadaMedia (4.9)0.97%—Learnpress Backup MigrationAI6/6/202623/7/2026
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, 4.1.4 via the 'import-user-file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read…
AplazadaBaja (3.8)0.39%—Wpvivid Backup MigrationAI6/6/202623/7/2026
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all versions up to, and including, 0.9.128. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.1)1.1%—Cluster-admin Backup-datastoreAI5/6/202617/6/2026
An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.
AnalizadaMedia (4.3)0.28%—Synology Hyper Backup3/6/202622/7/2026
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.
AnalizadaMedia (4.1)0.30%—Synology Hyper Backup3/6/202622/7/2026
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified…
AnalizadaAlta (7.8)0.12%—Synology Hyper Backup Explorer3/6/202622/7/2026
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
AnalizadaAlta (7.8)0.12%—Synology Active Backup FOR Business Recovery Media Creator3/6/202622/7/2026
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
AplazadaCrítica (9)0.48%—Comet BackupAI28/5/202617/6/2026
Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices.
AplazadaAlta (8.6)0.47%—Veeam Backup AND ReplicationAI28/5/202617/6/2026
A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.
AplazadaAlta (7.5)0.52%—Revmakx Backup AND Staging BY WP Time CapsuleAI27/5/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Password Recovery Exploitation.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.25.
AnalizadaMedia (5.6)0.09%—Synology Active Backup FOR Business Agent27/5/202630/9/2026
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
AnalizadaAlta (8.6)0.37%—Synology Active Backup FOR Business27/5/202630/9/2026
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
AplazadaAlta (8.7)0.40%—Backup AND RestoreAI16/5/202617/6/2026
WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers can send POST requests to admin-ajax.php with crafted file_name and folder_name parameters to delete arbitrary files…
AplazadaMedia (6.9)0.67%—Supsystic BackupAI16/5/202629/9/2026
Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access sensitive files like…
AplazadaAlta (7.5)0.57%—Database Backup FOR WordpressAI14/5/202617/6/2026
The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated…
AplazadaAlta (8.1)0.57%—Database Backup FOR WordpressAI14/5/202617/6/2026
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter.…
AplazadaAlta (7.5)0.50%—Deliciousbrains Database BackupAI14/5/202617/6/2026
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check. This makes it possible for unauthenticated attackers to export database tables,…
AplazadaAlta (8.7)0.31%—Inisev Backup MigrationAI5/5/202617/6/2026
WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated attackers to download complete database backups by accessing predictable file paths. Attackers can enumerate backup directories through configuration files and complete logs, then construct direct…
Pendiente de análisisCrítica (9.9)0.46%—Comet BackupAI4/5/202617/6/2026
A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call.
AnalizadaAlta (8.6)0.21%—Entersrl Iperius Backup22/4/202617/6/2026
Iperius Backup 5.8.1 contains a local buffer overflow vulnerability in the structured exception handling (SEH) mechanism that allows local attackers to execute arbitrary code by supplying a malicious file path. Attackers can create a backup job with a crafted payload in the external file location field that triggers a…
AplazadaMedia (4.9)0.60%—JetbackupAI17/4/202617/6/2026
The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Directory Deletion in versions up to and including 3.1.19.8. This is due to insufficient input validation on the fileName parameter in the file upload handler. The plugin sanitizes the fileName parameter…
Orbitaley — Vulnerabilidades