Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.37% | — | Azzaroco WP SuperbackupAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3. | |
| Aplazada | Alta (7.5) | 0.45% | — | Azzaroco WP SuperbackupAI | 31/12/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup.This issue affects WP SuperBackup: from n/a through <= 2.3.3. | |
| Aplazada | Alta (7.5) | 12% | 💥 PoC | Azzaroco WP SuperbackupAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3. | |
| Aplazada | Crítica (10) | 35% | 💥 Exploit | Azzaroco WP SuperbackupAI | 31/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Server.This issue affects WP SuperBackup: from n/a through <= 2.3.3. | |
| Aplazada | Media (4.9) | 0.85% | — | Database Backup AND Check Tables Automated With SchedulerAI | 24/12/2024 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the database_backup_ajax_download() function. This makes it possible for authenticated attackers, with administrator-level access and above, to… | |
| Aplazada | Media (4.3) | 0.51% | — | Webtoffee Wordpress Backup & MigrationAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WebToffee WordPress Backup & Migration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Backup & Migration: from n/a through 1.4.0. | |
| Aplazada | Crítica (9.8) | 3.5% | 💥 PoC | Ibroid Super Backup CloneAI | 13/12/2024 | 17/6/2026 | The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (4.3) | 0.38% | — | Tech-banker Backup BankAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Tech Banker Backup Bank: WordPress Backup Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backup Bank: WordPress Backup Plugin: from n/a through 4.0.28. | |
| Aplazada | Crítica (9.8) | 23% | 💥 Exploit | WP Umbrella Update Backup Restore AND MonitoringAI | 8/12/2024 | 17/6/2026 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the… | |
| Analizada | Crítica (9.5) | 2.3% | — | Qnap Hybrid Backup Sync | 6/12/2024 | 17/6/2026 | An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 25.1.1.673 and later | |
| Analizada | Media (4.3) | 0.36% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial target and potentially leading to broader… | |
| Analizada | Media (6.5) | 0.41% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a remote management interface. This can be achieved using a session object that allows for credential enumeration and exploitation, leading to the leak of… | |
| Analizada | Alta (8.8) | 0.39% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate used for authentication on a specific port. This can result in unauthorized access, enabling the… | |
| Analizada | Alta (8.1) | 15% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service account privileges. The vulnerability is… | |
| Analizada | Alta (8.1) | 0.34% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially leading to Denial of Service (DoS) and… | |
| Analizada | Alta (8.8) | 0.50% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to system-level access. This allows the attacker to upload files to the server with elevated privileges. The vulnerability exists because remote… | |
| Analizada | Media (6.5) | 0.28% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an external protocol, ultimately retrieving the credentials using a malicious setup on the attacker's side. This exposes sensitive data, which could… | |
| Analizada | Alta (8.8) | 0.76% | — | Veeam Backup & Replication | 4/12/2024 | 17/6/2026 | A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The… | |
| Aplazada | Media (4.9) | 0.54% | — | Toolstack Cyan BackupAI | 18/11/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Greg Ross CYAN Backup cyan-backup allows Path Traversal.This issue affects CYAN Backup: from n/a through <= 2.5.3. | |
| Analizada | Alta (7.8) | 0.23% | — | Veritas Netbackup | 18/11/2024 | 17/6/2026 | An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded,… | |
| Aplazada | Alta (8.8) | 0.23% | — | Skipstorm SK WP Settings BackupAI | 16/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object Injection.This issue affects SK WP Settings Backup: from n/a through <= 1.0. | |
| Analizada | Crítica (9.8) | 94% | 💥 Exploit | Revmakx Backup AND Staging BY WP Time Capsule | 16/11/2024 | 17/6/2026 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible for unauthenticated attackers to upload… | |
| Analizada | Alta (8.8) | 0.65% | — | Wpvivid Migration, Backup, Staging | 14/11/2024 | 17/6/2026 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization of untrusted input in the 'replace_row_data' and 'replace_serialize_data' functions. This makes it possible for unauthenticated attackers to inject a PHP… | |
| Aplazada | Baja (3.3) | 0.21% | — | Acronis Backup Plugin FOR Cpanel AND WHMAI | 11/11/2024 | 17/6/2026 | Sensitive information disclosure during file browsing due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892. | |
| Aplazada | Media (5.5) | 0.20% | — | Acronis Backup Plugin FOR Cpanel AND WHMAIAcronis Backup Extension FOR PleskAIAcronis Backup Plugin FOR DirectadminAI | 11/11/2024 | 17/6/2026 | Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build… |