Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.17% | — | Hasleo Backup SuiteAI | 27/10/2025 | 17/6/2026 | A weakness has been identified in Hasleo Backup Suite up to 5.2. Impacted is an unknown function of the component HasleoImageMountService/HasleoBackupSuiteService. This manipulation causes unquoted search path. The attack is restricted to local execution. The attack's complexity is rated as high. The exploitability is… | |
| Aplazada | Media (4.7) | 0.41% | — | Hasleo Backup SuiteAI | 10/1/2025 | 17/6/2026 | Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function. | |
| Modificada | Alta (7.2) | 22% | — | Ahsay Cloud Backup Suite | 21/9/2022 | 17/6/2026 | Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote… | |
| Modificada | Alta (8.8) | 1.4% | — | Ahsay Cloud Backup Suite | 6/1/2020 | 17/6/2026 | An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in the X-RSW-custom-encode-path HTTP header, and the content in the HTTP request body. It is possible to upload a file into any directory of… | |
| Modificada | Alta (8.8) | 75% | — | Ahsay Cloud Backup Suite | 26/7/2019 | 17/6/2026 | An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full access to the system, as the configured user (e.g.,… | |
| Modificada | Alta (7.5) | 13% | — | Ahsay Cloud Backup Suite | 26/7/2019 | 17/6/2026 | An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the content of files without authentication. | |
| Modificada | Alta (7.5) | 2.5% | — | Ahsay Cloud Backup Suite | 26/7/2019 | 17/6/2026 | An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. On the /cbs/system/ShowAdvanced.do "File Explorer" screen, it is possible to change the directory in the JavaScript code. If changed to (for example) "C:" then one can browse the whole server. | |
| Modificada | Alta (7.2) | 1.3% | — | Ahsay Cloud Backup Suite | 26/7/2019 | 17/6/2026 | An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. With a valid administrator account, the "Move / Import / Export Users" screen has an Import Users option. This option accepts a ZIP archive containing a users.xml file that can trigger XXE. | |
| Modificada | Media (6.1) | 0.83% | — | Ahsay Cloud Backup Suite | 26/7/2019 | 17/6/2026 | An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the attacker to retrieve the admin's cookie and take over the account. |