Vulnerability index

Browse CVEs

156 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2021-34800 Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147 Agent Patch available Fix from $1,9502021-11-29 MEDIUM 6.1 CVE-2021-44201 Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) befor… Cyber Protect 15+ Fix from $1,6002021-11-29 MEDIUM 5.4 CVE-2021-44200 Self cross-site scripting (XSS) was possible on devices page. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before b… Cyber Protect 15+ Fix from $1,6002021-11-29 MEDIUM 5.4 CVE-2021-44202 Stored cross-site scripting (XSS) was possible in activity details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) be… Cyber Protect 15+ Fix from $1,6002021-11-29 MEDIUM 5.4 CVE-2021-44203 Stored cross-site scripting (XSS) was possible in protection plan details. The following products are affected: Acronis Cyber Protect 15 (Windows, Li… Cyber Protect 15+ Fix from $1,6002021-11-29 HIGH 7.8 CVE-2021-44198 DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035 Cyber Protect 15+ Fix from $1,9502021-11-29 MEDIUM 5.5 CVE-2021-44199 DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Ag… Agent 15+ Fix from $1,6002021-11-29 HIGH 7.8 CVE-2021-38086 Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via D… Cyber Protect 15+ Fix from $1,9502021-08-12 HIGH 7.8 CVE-2021-38088 Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking. Cyber Protect 15+ Fix from $1,9502021-08-12 MEDIUM 6.1 CVE-2021-38087 Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009. Cyber Protect 15+ Fix from $1,6002021-08-12 HIGH 8.1 CVE-2021-32581 Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653, Acronis… Cyber Protect Cloud 15.0.26653 / 15.0.27009+ Fix from $1,9502021-08-05 HIGH 7.8 CVE-2021-32579 Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (wh… True Image Mitigation only Fix from $1,9502021-08-05 HIGH 7.8 CVE-2021-32580 Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking. True Image Mitigation only Fix from $1,9502021-08-05 HIGH 7.8 CVE-2021-32576 Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 1 of 2). True Image Mitigation only Fix from $1,9502021-08-05 HIGH 7.8 CVE-2021-32577 Acronis True Image prior to 2021 Update 5 for Windows allowed local privilege escalation due to insecure folder permissions. True Image Mitigation only Fix from $1,9502021-08-05 HIGH 7.8 CVE-2021-32578 Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 2 of 2). True Image Mitigation only Fix from $1,9502021-08-05 HIGH 7.5 CVE-2020-14999 A logic bug in system monitoring driver of Acronis Agent after 12.5.21540 and before 12.5.23094 allowed to bypass Windows memory protection and acces… Agent after 12.5.23094 Fix from $1,9502021-07-30 HIGH 7.8 CVE-2020-15495 Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service configuration. True Image Mitigation only Fix from $1,9502021-07-15 HIGH 7.8 CVE-2020-25736 Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration. True Image No fix yet Fix from $1,9502021-07-15 MEDIUM 6.7 CVE-2020-25593 Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions. True Image after 2021 Fix from $1,6002021-07-15 HIGH 7.8 CVE-2020-15496 Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions. True Image 2021+ Fix from $1,9502021-07-15 HIGH 7.8 CVE-2020-9450 An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe exposes a REST API that can be used by everyone, even unpr… True Image 2020 No fix yet Fix from $1,9502021-05-25 HIGH 7.8 CVE-2020-9452 An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe includes functionality to quarantine files by copying a su… True Image 2020 No fix yet Fix from $1,9502021-05-25 MEDIUM 5.5 CVE-2020-9451 An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe keeps a log in a folder where unprivileged users have writ… True Image 2020 No fix yet Fix from $1,6002021-05-25 HIGH 7.5 CVE-2020-35556 An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, informati… Cyber Protect 15+ Fix from $1,9502021-02-22 MEDIUM 6.1 CVE-2020-35664 An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in the console. Cyber Protect 15+ Fix from $1,6002021-02-22 HIGH 7.8 CVE-2020-35145 Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components,… True Image after 2021 Fix from $1,9502021-01-29 HIGH 7.8 CVE-2020-10138 Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins… Cyber Backup 12.5 / 15+ Fix from $1,9502020-10-21 HIGH 7.8 CVE-2020-10139 Acronis True Image 2021 includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis True … True Image Mitigation only Fix from $1,9502020-10-21 HIGH 7.3 CVE-2020-10140 Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C… True Image Mitigation only Fix from $1,9502020-10-21