Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.15% | — | Opentext Carbonite Safe Server BackupAI | 24/2/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Carbonite Safe Server Backup allows Code Injection. The vulnerability could be exploited through an open port, potentially allowing unauthorized access. This issue affects Carbonite Safe Server Backup: through 6.8.3. | |
| Aplazada | Alta (7.1) | 0.26% | — | Softland FbackupAI | 17/2/2026 | 17/6/2026 | A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Program Files\Common Files\microsoft shared\ink\HID.dll of the component Backup/Restore. The manipulation results in link following. The attack needs to be approached locally. The exploit has been… | |
| Analizada | Media (6.5) | 0.26% | — | IBM DB2 Merge Backup | 17/2/2026 | 17/6/2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack. | |
| Analizada | Media (6.5) | 0.26% | — | IBM DB2 Merge Backup | 17/2/2026 | 17/6/2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an authenticated user to cause the program to crash due to the incorrect calculation of a buffer size. | |
| Analizada | Alta (7.5) | 0.19% | — | IBM DB2 Merge Backup | 17/2/2026 | 17/6/2026 | IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources. | |
| Aplazada | Alta (8.5) | 0.17% | — | Intego Personal BackupAI | 12/2/2026 | 17/6/2026 | Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones, contains a local privilege escalation vulnerability. Backup task definitions are stored in a location writable by non-privileged users while being processed with elevated privileges. By crafting a… | |
| Aplazada | Media (4.6) | 0.34% | — | Backup KEY RecoveryAI | 11/2/2026 | 17/6/2026 | Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by supplying an overly long registration key. Attackers can generate a 1000-character payload file and paste it into the registration key field to trigger an application crash. | |
| Aplazada | Media (4.6) | 0.32% | — | Backup KEY RecoveryAI | 11/2/2026 | 17/6/2026 | Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash. | |
| Aplazada | Crítica (9.8) | 33% | 💥 Exploit | Wpvivid Backup MigrationAI | 11/2/2026 | 17/6/2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writing uploaded files.… | |
| Aplazada | Alta (8.5) | 0.37% | — | Netgate Data BackupAI | 5/2/2026 | 17/6/2026 | NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific directory locations. | |
| Aplazada | Alta (8.5) | 0.17% | — | Veritas NetbackupAI | 1/2/2026 | 17/6/2026 | Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe to inject malicious code that would execute with… | |
| Aplazada | Alta (8.5) | 0.17% | — | Acer Backup ManagerAINTI IschedulesvcAI | 16/1/2026 | 17/6/2026 | Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\NTI\Acer Backup Manager\ to inject malicious executables that would run with… | |
| Aplazada | Media (6.7) | 0.41% | — | Backup KEY RecoveryAI | 16/1/2026 | 17/6/2026 | Backup Key Recovery 2.2.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a large buffer of 256 repeated characters into the registration key field to trigger application instability and potential crash. | |
| Modificada | Alta (8.5) | 0.23% | — | Cobiansoft Cobian Backup | 13/1/2026 | 17/6/2026 | Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CobianReflectorService to inject malicious code that will execute with LocalSystem permissions during service… | |
| Analizada | Crítica (9) | 1.5% | 💥 PoC | Veeam Backup & Replication | 8/1/2026 | 7/10/2026 | This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter. | |
| Analizada | Crítica (9) | 0.63% | — | Veeam Backup & Replication | 8/1/2026 | 7/10/2026 | This vulnerability allows a Backup or Tape Operator to write files as root. | |
| Analizada | Crítica (9.1) | 1.0% | — | Veeam Backup & Replication | 8/1/2026 | 7/10/2026 | This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter. | |
| Analizada | Crítica (9.8) | 0.39% | — | Veeam Backup & Replication | 8/1/2026 | 7/10/2026 | This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file. | |
| Analizada | Alta (7) | 0.27% | — | Qnap Hybrid Backup Sync | 2/1/2026 | 25/7/2026 | An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup… | |
| Analizada | Alta (7) | 0.24% | — | Qnap Hybrid Backup Sync | 2/1/2026 | 17/6/2026 | A generation of error message containing sensitive information vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read application data. We have already fixed the vulnerability in the following version: HBS 3 Hybrid… | |
| Modificada | Alta (8.1) | 0.19% | — | Everestthemes Everest Backup | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Path Traversal.This issue affects Everest Backup: from n/a through <= 2.3.11. | |
| Aplazada | Alta (7.3) | 0.18% | — | Msp360 Free BackupAI | 23/12/2025 | 17/6/2026 | MSP360 Free Backup Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSP360 Free Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Aplazada | Alta (8.5) | 0.15% | — | Cobian Backup GravityAI | 22/12/2025 | 17/6/2026 | Cobian Backup Gravity 11.2.0.582 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the CobianBackup11 service to inject malicious code that would execute with LocalSystem… | |
| Modificada | Media (6.9) | 0.22% | — | Cobiansoft Backup 11 | 22/12/2025 | 17/6/2026 | Cobian Backup 11 Gravity 11.2.0.582 contains a denial of service vulnerability in the FTP password input field that allows attackers to crash the application. Attackers can generate a specially crafted 800-byte buffer and paste it into the password field to trigger an application crash. | |
| Aplazada | Baja (2.7) | 0.41% | — | Wpvivid Backup MigrationAI | 21/12/2025 | 17/6/2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This is due to the check_filesystem_permissions() function not properly restricting the directories that can be created, or in what location.… |