Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

177 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.8)0.10%—Veritas Netbackup Flex OSAI18/9/202618/9/2026
An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitation could expose sensitive system configuration and credential material stored on the…
AplazadaCrítica (9.4)0.34%—Veritas Netbackup FlexAI18/9/202618/9/2026
An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. Successful exploitation grants the attacker an unrestricted root shell with full…
AplazadaCrítica (9.4)0.67%—Veritas Netbackup FlexAI18/9/202618/9/2026
An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permissions. Successful exploitation grants the attacker unrestricted control over the Flex…
AplazadaAlta (8.5)0.17%—Veritas NetbackupAI1/2/202617/6/2026
Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe to inject malicious code that would execute with…
AnalizadaAlta (7.8)0.23%—Veritas Netbackup18/11/202417/6/2026
An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded,…
AplazadaMedia (6.8)0.37%—Veritas NetbackupAIVeritas Netbackup ApplianceAI3/5/202417/6/2026
A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Appliance before 5.4. By design, only the cloud administrator should be able to disable the retention lock of Governance mode images. This vulnerability allowed a NetBackup administrator to modify the…
AnalizadaAlta (7.1)0.17%—Veritas Netbackup26/4/202417/6/2026
An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files.
AnalizadaCrítica (9.8)0.99%—Veritas NetbackupVeritas Netbackup Appliance7/3/202417/6/2026
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
ModificadaCrítica (9.8)0.40%—Veritas Netbackup Snapshot Manager11/8/202317/6/2026
A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service. Exploiting this impacts the confidentiality and…
ModificadaAlta (7.2)0.62%—Veritas Netbackup Appliance29/6/202317/6/2026
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.
ModificadaMedia (6.1)0.44%—Veritas Netbackup Appliance Firmware10/4/202317/6/2026
Veritas Appliance v4.1.0.1 is affected by Host Header Injection attacks. HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would just cause the request to be sent to a completely different Domain/IP address.
ModificadaMedia (6.1)0.49%—Veritas Netbackup Opscenter5/4/202317/6/2026
Veritas NetBackUp OpsCenter Version 9.1.0.1 is vulnerable to Reflected Cross-site scripting (XSS). The Web App fails to adequately sanitize special characters. By leveraging this issue, an attacker is able to cause arbitrary HTML and JavaScript code to be executed in a user's browser.
ModificadaMedia (5.3)0.17%—Veritas Aptare IT AnalyticsVeritas Netbackup IT Analytics24/3/202317/6/2026
An issue was discovered in Veritas NetBackup IT Analytics 11 before 11.2.0. The application upgrade process included unsigned files that could be exploited and result in a customer installing unauthentic components. A malicious actor could install rogue Collector executable files (aptare.jar or upgrademanager.zip) on…
ModificadaAlta (7.8)0.19%—Veritas Netbackup23/3/202317/6/2026
An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system.
ModificadaAlta (7.1)0.15%—Veritas Netbackup23/3/202317/6/2026
An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.
ModificadaCrítica (9.8)1.3%—Veritas Access ApplianceVeritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.
ModificadaAlta (8.8)1.5%—Veritas Access ApplianceVeritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal.
ModificadaAlta (8.8)0.70%—Veritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands.
ModificadaAlta (8.8)0.58%—Veritas Access ApplianceVeritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.
ModificadaAlta (8.8)0.58%—Veritas Netbackup Flex Scale Appliance4/12/202217/6/2026
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands.
ModificadaAlta (8.8)0.80%—Veritas Netbackup17/11/202217/6/2026
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.
ModificadaAlta (7.1)0.21%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbx_exchange registration code.
ModificadaCrítica (9.8)0.61%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.
ModificadaMedia (5.5)0.19%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbx_exchange during registration and cause a NULL pointer exception, effectively crashing the pbx_exchange process.
ModificadaAlta (7.5)0.67%—Veritas Netbackup3/10/202217/6/2026
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a Path traversal attack through the DiscoveryService service.