Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.16%—Wordpress SQL BackupAI24/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Anthony WordPress SQL Backup wordpress-sql-backup allows Stored XSS.This issue affects WordPress SQL Backup: from n/a through <= 3.5.2.
AnalizadaAlta (8.8)24%—Veeam Backup & Replication20/3/202517/6/2026
A vulnerability allowing remote code execution (RCE) for domain users.
AnalizadaMedia (6.3)0.52%—Qnap Hybrid Backup Sync7/3/202517/6/2026
A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to modify memory or crash processes. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.4.952 and later
AnalizadaAlta (8.6)94%⚠ Explotación activa💥 ExploitNakivo Backup & Replication Director4/3/202524/9/2026
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).
AnalizadaAlta (7.8)0.34%—Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+23/3/202517/6/2026
Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service.
AnalizadaAlta (7.8)0.50%💥 PoCParagon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+23/3/202517/6/2026
Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by the memmove function, which does not validate or sanitize user controlled input, allowing an attacker the ability to write arbitrary kernel memory and perform privilege escalation.
AnalizadaMedia (5.1)0.35%—Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+23/3/202517/6/2026
Various Paragon Software products contain a null pointer dereference vulnerability within biontdrv.sys that is caused by a lack of a valid MasterLrp structure in the input buffer, allowing an attacker to execute arbitrary code in the kernel, facilitating privilege escalation.
AnalizadaAlta (8.4)0.37%—Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+23/3/202517/6/2026
Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to execute arbitrary code on the victim machine.
AnalizadaAlta (7.8)0.34%—Paragon-software Paragon Backup & RecoveryParagon-software Paragon Disk WiperParagon-software Paragon Drive CopyParagon-software Paragon Hard Disk Manager+23/3/202517/6/2026
Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits.
AplazadaAlta (7.2)1.0%—Database Backup AND Check Tables Automated With SchedulerAI1/3/202517/6/2026
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'database_backup_ajax_delete' function in all versions up to, and including, 2.35. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.2)0.59%—Database Backup AND Check Tables Automated With Scheduler 2024AI1/3/202517/6/2026
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35 via the /dashboard/backup.php file. This makes it possible for authenticated attackers, with Administrator-level access and above, to…
AplazadaMedia (5.5)0.19%—Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAI27/2/202517/6/2026
Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux)…
AplazadaMedia (6.5)0.26%—Ieonly EZ SQL Reports Shortcode Widget AND DB BackupAI25/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup elisqlreports allows Stored XSS.This issue affects EZ SQL Reports Shortcode Widget and DB Backup: from n/a through <= 5.21.35.
AnalizadaAlta (7.2)2.3%💥 PoCWpvivid Backup & Migration22/2/202517/6/2026
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level access…
AplazadaMedia (4.9)0.52%—Fahadmahmood Keep Backup DailyAI16/2/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Fahad Mahmood Keep Backup Daily keep-backup-daily allows Path Traversal.This issue affects Keep Backup Daily: from n/a through <= 2.1.0.
AnalizadaBaja (2.7)0.48%—Synology Active Backup FOR Business Agent13/2/202517/6/2026
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to read specific files containing…
AnalizadaMedia (6.5)0.40%—Synology Active Backup FOR Business Agent13/2/202517/6/2026
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users to write specific files via unspecified vectors.
AnalizadaMedia (6.5)0.57%—Synology Active Backup FOR Business Agent13/2/202517/6/2026
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to delete arbitrary files via unspecified…
AnalizadaAlta (7.2)0.34%—Veeam Backup14/1/202517/6/2026
Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
AplazadaMedia (4.7)0.41%💥 PoCHasleo Backup SuiteAI10/1/202517/6/2026
Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.
AplazadaAlta (7.5)0.51%—Wpseeds WP Database BackupAI9/1/202517/6/2026
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.3 via publicly accessible back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including all…
ModificadaCrítica (9.8)0.40%—Wpvivid Migration, Backup, Staging7/1/202517/6/2026
Missing Authorization vulnerability in wpvividplugins WPvivid Backup and Migration wpvivid-backuprestore allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPvivid Backup and Migration: from n/a through <= 0.9.106.
AplazadaAlta (8.8)0.80%—Backupbliss Backup MigrationAI4/1/202517/6/2026
The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a…
AplazadaMedia (5.4)0.38%—Webtoffee Wordpress Backup AND MigrationAI2/1/202517/6/2026
Missing Authorization vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Backup & Migration: from n/a through <= 1.4.1.
AplazadaAlta (7.1)0.26%—Azzaroco WP SuperbackupAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Reflected XSS.This issue affects WP SuperBackup: from n/a through <= 2.3.3.