Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
1217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.30% | — | Nimesa Backup AND RecoveryAI | 7/7/2025 | 17/6/2026 | Server-side request forgery (SSRF) vulnerability exists n multiple versions of Nimesa Backup and Recovery, If this vulnerability is exploited, unintended requests may be sent to internal servers. | |
| Aplazada | Crítica (9.3) | 1.3% | — | Nimesa Backup AND RecoveryAI | 7/7/2025 | 17/6/2026 | An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be executed on the server where the product is running. | |
| Analizada | Alta (7.2) | 55% | 💥 Exploit | Wpvivid Migration, Backup, Staging | 3/7/2025 | 17/6/2026 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.24% | — | Ieonly EZ SQL Reports Shortcode Widget AND DB Backup | 29/6/2025 | 17/6/2026 | The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SQLREPORT shortcode in all versions up to, and including, 5.25.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (4.9) | 19% | — | Veeam Backup & Replication | 19/6/2025 | 17/6/2026 | A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code. | |
| Analizada | Alta (8.8) | 24% | — | Veeam Backup & Replication | 19/6/2025 | 17/6/2026 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user | |
| Aplazada | Alta (7.1) | 0.28% | — | Revmakx Backup AND Staging BY WP Time CapsuleAIRevmakx WP Time CapsuleAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Reflected XSS.This issue affects Backup and Staging by WP Time Capsule: from n/a through <= 1.22.23. | |
| Aplazada | Media (4.3) | 0.16% | — | Everestthemes Everest BackupAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Cross Site Request Forgery.This issue affects Everest Backup: from n/a through <= 2.3.3. | |
| Analizada | Alta (8.5) | 0.42% | — | Msp360 Backup | 22/5/2025 | 17/6/2026 | An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15). | |
| Analizada | Media (6.1) | 0.23% | — | Nitsantech Ns-backup | 21/5/2025 | 17/6/2026 | The ns_backup extension through 13.0.0 for TYPO3 allows XSS. | |
| Aplazada | Media (6.8) | 0.75% | — | Typo3 NS BackupAI | 21/5/2025 | 17/6/2026 | The ns_backup extension through 13.0.0 for TYPO3 allows command injection. | |
| Aplazada | Alta (8.6) | 0.35% | — | Typo3 NS BackupAI | 21/5/2025 | 17/6/2026 | The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location. | |
| Aplazada | Alta (8.4) | 0.16% | — | Portworx PX BackupAI | 19/5/2025 | 17/6/2026 | A vulnerability exists in PX Backup whereby sensitive information may be logged under specific conditions. | |
| Modificada | Media (6.5) | 1.1% | 💥 PoC | Synology Active Backup FOR Microsoft 365 | 16/5/2025 | 17/6/2026 | A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vectors. | |
| Analizada | Media (5.4) | 0.30% | — | Toolstack Cyan Backup | 15/5/2025 | 17/6/2026 | The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.4) | 0.30% | — | Toolstack Cyan Backup | 15/5/2025 | 17/6/2026 | The CYAN Backup WordPress plugin before 2.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.30% | — | Wpproking Backup Database | 15/5/2025 | 17/6/2026 | The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Alta (8.5) | 0.44% | — | Msp360 Backup | 1/5/2025 | 17/6/2026 | An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22). | |
| Aplazada | Media (5.9) | 0.40% | — | Webtoffee Wordpress Backup AND MigrationAI | 17/4/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Retrieve Embedded Sensitive Data.This issue affects WordPress Backup & Migration: from n/a through <= 1.5.3. | |
| Analizada | Media (6.7) | 0.20% | — | Oracle Secure Backup | 15/4/2025 | 17/6/2026 | Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and 18.1.0.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Secure Backup executes to compromise Oracle… | |
| Aplazada | Alta (8.6) | 0.52% | — | Nakivo Backup AND ReplicationAI | 8/4/2025 | 17/6/2026 | An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse the XML response. | |
| Aplazada | Media (5.4) | 0.49% | — | TIM Nguyen 1-click Backup Restore DatabaseAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Tim Nguyen 1-Click Backup & Restore Database 1-click-backup-restore-database-by-sunbytes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 1-Click Backup & Restore Database: from n/a through <= 1.0.3. | |
| Aplazada | Media (4.3) | 0.40% | — | Josselynj Pcloud BackupAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in josselynj pCloud Backup pcloud-backup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects pCloud Backup: from n/a through <= 1.0.1. | |
| Aplazada | Alta (8.2) | 0.21% | — | Ieonly EZ SQL Reports Shortcode Widget AND DB BackupAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup elisqlreports allows SQL Injection.This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through <= 5.25.08. | |
| Aplazada | Alta (7.1) | 0.18% | — | Ieonly EZ SQL Reports Shortcode Widget AND DB BackupAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup elisqlreports allows Stored XSS.This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through <= 5.25.08. |