Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
325 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.14% | — | Acronis Cyber Files | 17/10/2024 | 17/6/2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. | |
| Analizada | Media (5.7) | 0.25% | — | Acronis Cyber Files | 17/10/2024 | 17/6/2026 | Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. | |
| Analizada | Crítica (9.1) | 0.27% | — | Acronis Cyber Protect | 15/10/2024 | 17/6/2026 | Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690. | |
| Analizada | Alta (7.5) | 0.17% | — | Acronis Cyber Protect | 15/10/2024 | 17/6/2026 | Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690. | |
| Analizada | Media (4.3) | 0.22% | — | Acronis Cyber Protect | 15/10/2024 | 17/6/2026 | Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690. | |
| Analizada | Media (4.3) | 0.22% | — | Acronis Cyber Protect | 15/10/2024 | 17/6/2026 | Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690. | |
| Analizada | Media (4.3) | 0.22% | — | Acronis Cyber Protect | 15/10/2024 | 17/6/2026 | Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690. | |
| Aplazada | Media (4.7) | 0.14% | — | Acronis Cyber Protect Cloud AgentAI | 23/9/2024 | 17/6/2026 | Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565. | |
| Aplazada | Crítica (9.9) | 0.48% | — | Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAIAcronis Backup Plugin FOR DirectadminAI | 17/9/2024 | 17/6/2026 | Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis Backup plugin for DirectAdmin (Linux) before build 147. | |
| Aplazada | Media (6.7) | 0.14% | — | Acronis Cyber Protect Cloud AgentAIAcronis Cyber Protect 16AI | 16/9/2024 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235, Acronis Cyber Protect 16 (Windows) before build 39169. | |
| Aplazada | Media (6.5) | 0.17% | — | Acronis Cyber Protect Cloud AgentAI | 16/9/2024 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 38235. | |
| Modificada | Media (6.1) | 0.40% | — | Leira Cron Jobs | 13/9/2024 | 17/6/2026 | The Cron Jobs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can… | |
| Analizada | Alta (7.3) | 0.14% | — | Acronis Snap Deploy | 29/8/2024 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569. | |
| Analizada | Media (5.5) | 0.15% | — | Acronis Snap Deploy | 29/8/2024 | 17/6/2026 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 4569. | |
| Analizada | Alta (7.3) | 0.14% | — | Acronis Snap Deploy | 29/8/2024 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569. | |
| Aplazada | Alta (7.3) | 0.52% | — | Vixie CronAIOpenbsdAI | 20/8/2024 | 17/6/2026 | cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring. | |
| Analizada | Crítica (9.8) | 53% | ⚠ Explotación activa💥 Exploit | Acronis Cyber Infrastructure | 24/7/2024 | 17/6/2026 | Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build… | |
| Aplazada | Alta (7.8) | 0.64% | — | Acronis True ImageAIAcronis True Image OEMAI | 18/7/2024 | 17/6/2026 | Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True Image (macOS) before build 41396, Acronis True Image OEM (macOS) before build 42571. | |
| Analizada | Media (6.5) | 0.37% | — | Acronis Cyber Protect | 16/7/2024 | 17/6/2026 | Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984. | |
| Modificada | Media (4.4) | 0.13% | — | Acronis Cloud Manager | 14/6/2024 | 17/6/2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.24135.272. | |
| Aplazada | Media (6.8) | 0.15% | — | Acronis Cyber Protect Cloud AgentAI | 29/4/2024 | 17/6/2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758. | |
| Aplazada | Alta (8.2) | 0.20% | — | Acronis Cyber Protect Cloud AgentAIAcronis Cyber Protect 16AIAcronis True ImageAIAcronis True Image OEMAI | 29/4/2024 | 17/6/2026 | Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 37758, Acronis Cyber Protect 16 (Windows) before build 38690, Acronis True Image (Windows) before build 42386, Acronis True Image OEM (Windows) before… | |
| Aplazada | Alta (7.1) | 0.16% | — | Acronis Cyber Protect Cloud AgentAIAcronis Cyber ProtectAI | 29/4/2024 | 17/6/2026 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 37758, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186. | |
| Aplazada | Alta (7.1) | 0.16% | — | Acronis Cyber Protect Cloud AgentAIAcronis Cyber Protect 16AI | 29/4/2024 | 17/6/2026 | Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 37758, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169. | |
| Aplazada | Media (4.3) | 0.21% | — | Scott Kingsley Clark Crony Cronjob ManagerAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Kingsley Clark Crony Cronjob Manager.This issue affects Crony Cronjob Manager: from n/a through 0.5.0. |