Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

1217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.22%—Everestthemes Everest BackupAI3/12/202517/6/2026
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the process_status_unlink() function in all versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to…
AplazadaMedia (5.9)0.28%—Backupbliss Backup MigrationAI24/11/202517/6/2026
The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication.
AplazadaMedia (6.5)0.72%—Toolstack Cyan BackupAI8/11/202517/6/2026
The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' functionality in all versions up to, and including, 2.5.4. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on…
AplazadaMedia (6.5)0.32%—Gaurav Aggarwal Backup AND MoveAI6/11/202517/6/2026
Missing Authorization vulnerability in Gaurav Aggarwal Backup and Move backup-and-move allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backup and Move: from n/a through <= 0.1.
AnalizadaAlta (8.8)1.0%—Veeam Backup & Replication31/10/202517/6/2026
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
ModificadaCrítica (9.9)0.85%—Veeam Backup & Replication31/10/202517/6/2026
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.
AplazadaMedia (6.4)0.17%—Hasleo Backup SuiteAI27/10/202517/6/2026
A weakness has been identified in Hasleo Backup Suite up to 5.2. Impacted is an unknown function of the component HasleoImageMountService/HasleoBackupSuiteService. This manipulation causes unquoted search path. The attack is restricted to local execution. The attack's complexity is rated as high. The exploitability is…
AplazadaMedia (5.3)0.34%—Everestthemes Everest BackupAI27/10/202517/6/2026
Missing Authorization vulnerability in everestthemes Everest Backup everest-backup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Everest Backup: from n/a through <= 2.3.8.
AplazadaAlta (7.1)0.25%—Nifty BackupsAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NickDuncan Nifty Backups nifty-backups allows Reflected XSS.This issue affects Nifty Backups: from n/a through <= 1.08.
AplazadaMedia (5.9)0.40%💥 PoCEverestthemes Everest BackupAI11/10/202517/6/2026
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'everest_process_status' AJAX action in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated…
AplazadaBaja (3.8)0.31%—Backupbolt Backup BoltAI3/10/202517/6/2026
The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4.1 via the process_backup_batch() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to download directories outside…
AplazadaMedia (5.9)0.38%—Managefy File Manager Code Editor AND BackupAI1/10/202517/6/2026
The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view information like full paths and full paths to backup…
AplazadaAlta (8.1)0.70%—BEI FEN Wordpress Backup PluginAI30/9/202517/6/2026
The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the 'task'. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing…
AplazadaMedia (6.5)0.66%💥 PoCSoftaculous BackuplyAI26/9/202517/6/2026
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete backup functionality in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Administrator-level access…
AplazadaAlta (8.6)1.1%—Typo3 NS BackupAI2/9/202517/6/2026
The ns_backup extension through 13.0.2 for TYPO3 allows command injection.
AplazadaAlta (7.1)0.13%—Xavier Media Xm-backupAI28/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Xavier Media XM-Backup xm-backup allows Stored XSS.This issue affects XM-Backup: from n/a through <= 0.9.1.
AplazadaMedia (4.9)0.50%💥 PoCManagefy File Manager Code Editor AND BackupAI28/8/202517/6/2026
The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.8 via the ajax_downloadfile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of…
AplazadaMedia (4.3)0.13%—Backupbolt Backup BoltAI27/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Backup Bolt Backup Bolt backup-bolt allows Cross Site Request Forgery.This issue affects Backup Bolt: from n/a through <= 1.5.0.
AnalizadaAlta (7.3)0.20%—Aomeitech Backupper Workstation20/8/202517/6/2026
AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of AOMEI Backupper Workstation. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…
AnalizadaCrítica (9.8)0.65%—Aomeitech Cyber Backup20/8/202517/6/2026
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AOMEI Cyber Backup. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaCrítica (9.8)0.65%—Aomei Cyber Backup20/8/202517/6/2026
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AOMEI Cyber Backup. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
AplazadaMedia (6.5)0.32%—Syedamirhussain91 DB BackupAI14/8/202517/6/2026
Missing Authorization vulnerability in syedamirhussain91 DB Backup db-backup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DB Backup: from n/a through <= 6.0.
AnalizadaCrítica (9.8)21%💥 ExploitWpseeds WP Database Backup25/7/202517/6/2026
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
AnalizadaAlta (7.5)1.7%—Mywebsiteadvisor Simple Backup19/7/202517/6/2026
The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the…
AplazadaCrítica (9.8)0.82%—Bears BackupAI17/7/202517/6/2026
The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0. This is due to the bbackup_ajax_handle() function not having a capability check, nor validating user supplied input passed directly to call_user_func(). This makes it possible for unauthenticated…