Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

1217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.30%—Nimesa Backup AND RecoveryAI7/7/202517/6/2026
Server-side request forgery (SSRF) vulnerability exists n multiple versions of Nimesa Backup and Recovery, If this vulnerability is exploited, unintended requests may be sent to internal servers.
AplazadaCrítica (9.3)1.3%—Nimesa Backup AND RecoveryAI7/7/202517/6/2026
An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be executed on the server where the product is running.
AnalizadaAlta (7.2)55%💥 ExploitWpvivid Migration, Backup, Staging3/7/202517/6/2026
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with…
AnalizadaMedia (5.4)0.24%—Ieonly EZ SQL Reports Shortcode Widget AND DB Backup29/6/202517/6/2026
The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SQLREPORT shortcode in all versions up to, and including, 5.25.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AnalizadaMedia (4.9)19%—Veeam Backup & Replication19/6/202517/6/2026
A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.
AnalizadaAlta (8.8)24%—Veeam Backup & Replication19/6/202517/6/2026
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
AplazadaAlta (7.1)0.28%—Revmakx Backup AND Staging BY WP Time CapsuleAIRevmakx WP Time CapsuleAI9/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Reflected XSS.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.23.
AplazadaMedia (4.3)0.16%—Everestthemes Everest BackupAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Cross Site Request Forgery.This issue affects Everest Backup: from n/a through <= 2.3.3.
AnalizadaAlta (8.5)0.42%—Msp360 Backup22/5/202517/6/2026
An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15).
AnalizadaMedia (6.1)0.23%—Nitsantech Ns-backup21/5/202517/6/2026
The ns_backup extension through 13.0.0 for TYPO3 allows XSS.
AplazadaMedia (6.8)0.75%—Typo3 NS BackupAI21/5/202517/6/2026
The ns_backup extension through 13.0.0 for TYPO3 allows command injection.
AplazadaAlta (8.6)0.35%—Typo3 NS BackupAI21/5/202517/6/2026
The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.
AplazadaAlta (8.4)0.16%—Portworx PX BackupAI19/5/202517/6/2026
A vulnerability exists in PX Backup whereby sensitive information may be logged under specific conditions.
ModificadaMedia (6.5)1.1%💥 PoCSynology Active Backup FOR Microsoft 36516/5/202517/6/2026
A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vectors.
AnalizadaMedia (5.4)0.30%—Toolstack Cyan Backup15/5/202517/6/2026
The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaMedia (5.4)0.30%—Toolstack Cyan Backup15/5/202517/6/2026
The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaMedia (4.8)0.30%—Wpproking Backup Database15/5/202517/6/2026
The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaAlta (8.5)0.44%—Msp360 Backup1/5/202517/6/2026
An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22).
AplazadaMedia (5.9)0.40%—Webtoffee Wordpress Backup AND MigrationAI17/4/202517/6/2026
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Retrieve Embedded Sensitive Data.This issue affects WordPress Backup & Migration: from n/a through <= 1.5.3.
AnalizadaMedia (6.7)0.20%—Oracle Secure Backup15/4/202517/6/2026
Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and 18.1.0.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Secure Backup executes to compromise Oracle…
AplazadaAlta (8.6)0.52%—Nakivo Backup AND ReplicationAI8/4/202517/6/2026
An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse the XML response.
AplazadaMedia (5.4)0.49%—TIM Nguyen 1-click Backup Restore DatabaseAI4/4/202517/6/2026
Missing Authorization vulnerability in Tim Nguyen 1-Click Backup & Restore Database 1-click-backup-restore-database-by-sunbytes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 1-Click Backup & Restore Database: from n/a through <= 1.0.3.
AplazadaMedia (4.3)0.40%—Josselynj Pcloud BackupAI1/4/202517/6/2026
Missing Authorization vulnerability in josselynj pCloud Backup pcloud-backup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects pCloud Backup: from n/a through <= 1.0.1.
AplazadaAlta (8.2)0.21%—Ieonly EZ SQL Reports Shortcode Widget AND DB BackupAI27/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup elisqlreports allows SQL Injection.This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through <= 5.25.08.
AplazadaAlta (7.1)0.18%—Ieonly EZ SQL Reports Shortcode Widget AND DB BackupAI27/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup elisqlreports allows Stored XSS.This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through <= 5.25.08.