Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.22% | — | Everestthemes Everest BackupAI | 3/12/2025 | 17/6/2026 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the process_status_unlink() function in all versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.9) | 0.28% | — | Backupbliss Backup MigrationAI | 24/11/2025 | 17/6/2026 | The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication. | |
| Aplazada | Media (6.5) | 0.72% | — | Toolstack Cyan BackupAI | 8/11/2025 | 17/6/2026 | The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' functionality in all versions up to, and including, 2.5.4. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on… | |
| Aplazada | Media (6.5) | 0.32% | — | Gaurav Aggarwal Backup AND MoveAI | 6/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Gaurav Aggarwal Backup and Move backup-and-move allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backup and Move: from n/a through <= 0.1. | |
| Analizada | Alta (8.8) | 1.0% | — | Veeam Backup & Replication | 31/10/2025 | 17/6/2026 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. | |
| Modificada | Crítica (9.9) | 0.85% | — | Veeam Backup & Replication | 31/10/2025 | 17/6/2026 | A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user. | |
| Aplazada | Media (6.4) | 0.17% | — | Hasleo Backup SuiteAI | 27/10/2025 | 17/6/2026 | A weakness has been identified in Hasleo Backup Suite up to 5.2. Impacted is an unknown function of the component HasleoImageMountService/HasleoBackupSuiteService. This manipulation causes unquoted search path. The attack is restricted to local execution. The attack's complexity is rated as high. The exploitability is… | |
| Aplazada | Media (5.3) | 0.34% | — | Everestthemes Everest BackupAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in everestthemes Everest Backup everest-backup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Everest Backup: from n/a through <= 2.3.8. | |
| Aplazada | Alta (7.1) | 0.25% | — | Nifty BackupsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NickDuncan Nifty Backups nifty-backups allows Reflected XSS.This issue affects Nifty Backups: from n/a through <= 1.08. | |
| Aplazada | Media (5.9) | 0.40% | 💥 PoC | Everestthemes Everest BackupAI | 11/10/2025 | 17/6/2026 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'everest_process_status' AJAX action in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated… | |
| Aplazada | Baja (3.8) | 0.31% | — | Backupbolt Backup BoltAI | 3/10/2025 | 17/6/2026 | The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4.1 via the process_backup_batch() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to download directories outside… | |
| Aplazada | Media (5.9) | 0.38% | — | Managefy File Manager Code Editor AND BackupAI | 1/10/2025 | 17/6/2026 | The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view information like full paths and full paths to backup… | |
| Aplazada | Alta (8.1) | 0.70% | — | BEI FEN Wordpress Backup PluginAI | 30/9/2025 | 17/6/2026 | The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the 'task'. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing… | |
| Aplazada | Media (6.5) | 0.66% | 💥 PoC | Softaculous BackuplyAI | 26/9/2025 | 17/6/2026 | The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete backup functionality in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Administrator-level access… | |
| Aplazada | Alta (8.6) | 1.1% | — | Typo3 NS BackupAI | 2/9/2025 | 17/6/2026 | The ns_backup extension through 13.0.2 for TYPO3 allows command injection. | |
| Aplazada | Alta (7.1) | 0.13% | — | Xavier Media Xm-backupAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Xavier Media XM-Backup xm-backup allows Stored XSS.This issue affects XM-Backup: from n/a through <= 0.9.1. | |
| Aplazada | Media (4.9) | 0.50% | 💥 PoC | Managefy File Manager Code Editor AND BackupAI | 28/8/2025 | 17/6/2026 | The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.8 via the ajax_downloadfile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of… | |
| Aplazada | Media (4.3) | 0.13% | — | Backupbolt Backup BoltAI | 27/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Backup Bolt Backup Bolt backup-bolt allows Cross Site Request Forgery.This issue affects Backup Bolt: from n/a through <= 1.5.0. | |
| Analizada | Alta (7.3) | 0.20% | — | Aomeitech Backupper Workstation | 20/8/2025 | 17/6/2026 | AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AOMEI Backupper Workstation. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Analizada | Crítica (9.8) | 0.65% | — | Aomeitech Cyber Backup | 20/8/2025 | 17/6/2026 | AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AOMEI Cyber Backup. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Crítica (9.8) | 0.65% | — | Aomei Cyber Backup | 20/8/2025 | 17/6/2026 | AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AOMEI Cyber Backup. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Aplazada | Media (6.5) | 0.32% | — | Syedamirhussain91 DB BackupAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in syedamirhussain91 DB Backup db-backup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DB Backup: from n/a through <= 6.0. | |
| Analizada | Crítica (9.8) | 21% | 💥 Exploit | Wpseeds WP Database Backup | 25/7/2025 | 17/6/2026 | The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system. | |
| Analizada | Alta (7.5) | 1.7% | — | Mywebsiteadvisor Simple Backup | 19/7/2025 | 17/6/2026 | The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the… | |
| Aplazada | Crítica (9.8) | 0.82% | — | Bears BackupAI | 17/7/2025 | 17/6/2026 | The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0. This is due to the bbackup_ajax_handle() function not having a capability check, nor validating user supplied input passed directly to call_user_func(). This makes it possible for unauthenticated… |