Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1213 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.35% | — | Royal Wordpress Backup Restore PluginAI | 10/4/2026 | 17/6/2026 | The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpr_pending_template' parameter in all versions up to, and including, 1.0.16 due to insufficient input validation. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.56% | — | Backupbliss Backup MigrationAI | 7/4/2026 | 30/9/2026 | The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to a missing capability check on the 'initializeOfflineAjax' function and lack of proper nonce verification. The endpoint only validates against hardcoded tokens which are publicly… | |
| Aplazada | Baja (1.1) | 0.13% | — | Entersrl Iperius BackupAI | 1/4/2026 | 17/6/2026 | A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to use of hard-coded cryptographic key . The attack must be carried out locally. This attack is characterized by high complexity. The exploitability is… | |
| Aplazada | Media (6.4) | 0.14% | — | Entersrl Iperius BackupAI | 25/3/2026 | 17/6/2026 | A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown functionality of the component Backup Job Configuration File Handler. The manipulation leads to improper privilege management. The attack must be carried out locally. The attack is considered to have… | |
| Aplazada | Baja (1.1) | 0.13% | — | Entersrl Iperius BackupAI | 25/3/2026 | 17/6/2026 | A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functionality of the component NTLM2 Handler. Executing a manipulation can lead to information disclosure. The attack is restricted to local execution. Attacks of this nature are highly complex. The… | |
| Aplazada | Media (6.4) | 0.16% | — | Entersrl Iperius BackupAI | 25/3/2026 | 17/6/2026 | A vulnerability was detected in Enter Software Iperius Backup up to 8.7.3. Affected is an unknown function of the file C:\ProgramData\IperiusBackup\Jobs\ of the component Backup Service. Performing a manipulation results in creation of temporary file with insecure permissions. The attack is only possible with local… | |
| Analizada | Crítica (9) | 0.34% | — | N2W Backup& Recovery | 25/3/2026 | 17/6/2026 | In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution. | |
| Aplazada | Alta (8.6) | 0.14% | — | Iperius BackupAI | 22/3/2026 | 17/6/2026 | Iperius Backup 6.1.0 contains a privilege escalation vulnerability that allows low-privilege users to execute arbitrary programs with elevated privileges by creating backup jobs. Attackers can configure backup jobs to execute malicious batch files or programs before or after backup operations, which run with the… | |
| Aplazada | Media (6.9) | 0.12% | — | Backup KEY RecoveryAI | 22/3/2026 | 17/6/2026 | Backup Key Recovery 2.2.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 or more characters into the Name field during registration to trigger a crash when submitting the form. | |
| Aplazada | Media (4.4) | 0.33% | — | Androidbubbles Keep Backup DailyAI | 21/3/2026 | 17/6/2026 | The Keep Backup Daily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the backup title alias (`val` parameter) in the `update_kbd_bkup_alias` AJAX action in all versions up to, and including, 2.1.2. This is due to insufficient input sanitization and output escaping. While `sanitize_text_field()`… | |
| Aplazada | Baja (2.7) | 0.42% | — | Androidbubbles Keep Backup DailyAI | 21/3/2026 | 17/6/2026 | The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and including, 2.1.1 via the `kbd_open_upload_dir` AJAX action. This is due to insufficient validation of the `kbd_path` parameter, which is only sanitized with `sanitize_text_field()` - a function that does not… | |
| Analizada | Crítica (9.9) | 1.1% | — | Veeam Backup & Replication | 12/3/2026 | 17/6/2026 | A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. | |
| Pendiente de análisis | Alta (8.8) | 0.22% | — | Veeam Backup AND ReplicationAI | 12/3/2026 | 17/6/2026 | A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers. | |
| Modificada | Crítica (9.1) | 1.3% | — | Veeam Backup & Replication | 12/3/2026 | 17/6/2026 | A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication. | |
| Modificada | Media (6.5) | 0.40% | — | Veeam Backup & Replication | 12/3/2026 | 17/6/2026 | A vulnerability allowing a low-privileged user to extract saved SSH credentials. | |
| Modificada | Crítica (9.9) | 1.2% | — | Veeam Backup & Replication | 12/3/2026 | 17/6/2026 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | |
| Modificada | Media (6.5) | 0.51% | — | Veeam Backup & Replication | 12/3/2026 | 17/6/2026 | A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. | |
| Analizada | Alta (8.8) | 1.1% | — | Veeam Backup & Replication | 12/3/2026 | 17/6/2026 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | |
| Analizada | Alta (8.8) | 1.1% | — | Veeam Backup & Replication | 12/3/2026 | 17/6/2026 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | |
| Analizada | Media (4.9) | 0.35% | — | Suse Rancher Backup AND Restore Operator | 4/3/2026 | 17/6/2026 | A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs. | |
| Aplazada | Alta (8.8) | 0.76% | — | Worry Proof BackupAI | 26/2/2026 | 17/6/2026 | The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traversal sequences to… | |
| Aplazada | Alta (8.6) | 0.15% | — | Opentext Carbonite Safe Server BackupAI | 24/2/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Carbonite Safe Server Backup allows Code Injection. The vulnerability could be exploited through an open port, potentially allowing unauthorized access. This issue affects Carbonite Safe Server Backup: through 6.8.3. | |
| Aplazada | Alta (7.1) | 0.26% | — | Softland FbackupAI | 17/2/2026 | 17/6/2026 | A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Program Files\Common Files\microsoft shared\ink\HID.dll of the component Backup/Restore. The manipulation results in link following. The attack needs to be approached locally. The exploit has been… | |
| Analizada | Media (6.5) | 0.26% | — | IBM DB2 Merge Backup | 17/2/2026 | 17/6/2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack. | |
| Analizada | Media (6.5) | 0.26% | — | IBM DB2 Merge Backup | 17/2/2026 | 17/6/2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to the incorrect calculation of a buffer size. |