Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
1211 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.31% | — | Backupsheep Wordpress Backup PluginAI | 1/10/2026 | 1/10/2026 | The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files… | |
| Aplazada | Alta (7.5) | 0.30% | — | BackupeaseAI | 30/9/2026 | 30/9/2026 | Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions. | |
| Aplazada | Alta (7.5) | 0.30% | — | Stifli Backup ToolsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions. | |
| Aplazada | Alta (7.5) | 0.29% | — | Wordpress Backup MigrationAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. | |
| Aplazada | Media (4.8) | 0.10% | — | Veritas Netbackup Flex OSAI | 18/9/2026 | 18/9/2026 | An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitation could expose sensitive system configuration and credential material stored on the… | |
| Aplazada | Crítica (9.4) | 0.34% | — | Veritas Netbackup FlexAI | 18/9/2026 | 18/9/2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Successful exploitation grants the attacker an unrestricted root shell with full… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Veritas Netbackup FlexAI | 18/9/2026 | 18/9/2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permissions. Successful exploitation grants the attacker unrestricted control over the Flex… | |
| Aplazada | Alta (7.2) | 0.46% | — | Servmask All-in-one WP Migration AND BackupAI | 18/9/2026 | 18/9/2026 | The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import an arbitrary site archive and gain… | |
| Analizada | Alta (7.8) | 0.23% | ⚠ Explotación activa | Acronis Backup | 17/9/2026 | 18/9/2026 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238. | |
| Aplazada | Crítica (9.6) | 0.25% | — | Webtotem BackupsAI | 12/9/2026 | 23/9/2026 | The WebTotem Backups WordPress plugin before 1.1.0 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to… | |
| Pendiente de análisis | Crítica (9.9) | 0.65% | — | Plesk Backup ManagerAI | 10/9/2026 | 10/9/2026 | Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. | |
| Aplazada | Alta (7.5) | 0.42% | — | Zhbackup Backup Restore MigrationAI | 10/9/2026 | 10/9/2026 | Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions. | |
| Pendiente de análisis | Alta (8) | 1.7% | — | Spatie Laravel-backup-restoreAISpatie Laravel-backupAI | 4/9/2026 | 10/9/2026 | laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4. | |
| Aplazada | Media (5.5) | 0.34% | — | Wpvivid Backup Migration StagingAI | 4/9/2026 | 8/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root. | |
| Aplazada | Media (5.5) | 0.38% | — | Wpvivid Backup Migration StagingAI | 4/9/2026 | 8/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing files. | |
| Pendiente de análisis | Alta (7.1) | 0.38% | — | Jenkins ThinbackupAI | 2/9/2026 | 3/9/2026 | Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system in backups. | |
| Aplazada | Alta (7.1) | 0.19% | — | JetbackupAI | 2/9/2026 | 3/9/2026 | The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site. | |
| Aplazada | Alta (8.7) | 0.52% | — | Androidbubbles Keep Backup DailyAI | 31/8/2026 | 8/9/2026 | Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` parameter without authentication. Attackers can predict the partially predictable… | |
| Aplazada | Media (6.6) | 0.26% | — | Wpvivid Backup Migration StagingAI | 30/8/2026 | 3/9/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lead to code execution. | |
| Aplazada | Media (4.4) | 0.25% | — | JetbackupAI | 27/8/2026 | 28/8/2026 | The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is not a Super Admin to download a full backup of the entire network, including every site's data and the shared… | |
| Aplazada | Alta (8.1) | 0.23% | — | Blogvault Backup AND StagingAIMalcare Wordpress Security PluginAITHE WP Remote WP RemoteAI | 26/8/2026 | 26/8/2026 | The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service,… | |
| Aplazada | Alta (8.8) | 1.4% | — | ALL IN ONE WP Migration AND BackupAI | 25/8/2026 | 28/9/2026 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Crítica (9.1) | 0.52% | — | Wpvivid Backup Migration StagingAI | 16/8/2026 | 26/8/2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing writable directory of the site, including the… | |
| Aplazada | Alta (7.2) | 0.46% | — | ALL IN ONE WP Migration AND BackupAI | 16/8/2026 | 26/8/2026 | The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network. | |
| Aplazada | Media (6.5) | 0.51% | — | Backupbliss Backup MigrationAI | 15/8/2026 | 26/8/2026 | The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing… |