Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.9)0.65%—Plesk Backup ManagerAI10/9/202610/9/2026
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
AplazadaAlta (8.5)0.17%—Acer Backup ManagerAINTI IschedulesvcAI16/1/202617/6/2026
Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\NTI\Acer Backup Manager\ to inject malicious executables that would run with…
ModificadaBaja (2.1)0.36%—Backup Manager4/9/200716/6/2026
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.
ModificadaAlta (7.2)0.33%—Backup Manager18/5/200716/6/2026
lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password as a plaintext command line argument, which allows local users to obtain this password by listing the process and its arguments, related to lib/backup-methods.sh.
ModificadaBaja (2.1)0.36%—Sukria Backup ManagerDebian Linux30/8/200516/6/2026
Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.
ModificadaBaja (2.1)0.33%—Backup Manager Backup-managerAI30/8/200516/6/2026
The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack.
ModificadaMedia (4.6)0.32%—Sukria Backup Manager11/7/200516/6/2026
Backup Manager 0.5.8a creates temporary files insecurely, which allows local users to conduct unauthorized file operations when a user is burning a CDR.
ModificadaMedia (6.4)0.99%—Sukria Backup Manager11/7/200516/6/2026
Backup Manager 0.5.8a creates an archive repository with world readable and writable permissions, which allows attackers to modify or read the repository.