Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-40386 Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code. Unitrends Backup after 10.5.5 Fix from $2,3002022-04-15 CRITICAL 9.8 CVE-2021-43033EPSS 6% An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary r… Unitrends Backup 10.5.5+ Fix from $2,3002021-12-06 CRITICAL 9.8 CVE-2021-43035 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowi… Unitrends Backup 10.5.5+ Fix from $2,3002021-12-06 CRITICAL 9.8 CVE-2021-43036 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak. Unitrends Backup 10.5.5+ Fix from $2,3002021-12-06 CRITICAL 9.8 CVE-2021-43042 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploita… Unitrends Backup 10.5.5+ Fix from $2,3002021-12-06 CRITICAL 9.8 CVE-2021-43044 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community. Unitrends Backup 10.5.5+ Fix from $2,3002021-12-06 HIGH 8.8 CVE-2021-43038 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL tr… Unitrends Backup 10.5.5+ Fix from $1,9502021-12-06 HIGH 8.8 CVE-2021-43040 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writabl… Unitrends Backup 10.5.5+ Fix from $1,9502021-12-06 HIGH 8.8 CVE-2021-43041 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vulnerability in the … Unitrends Backup 10.5.5+ Fix from $1,9502021-12-06 HIGH 7.8 CVE-2021-43034 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as th… Unitrends Backup 10.5.5+ Fix from $1,9502021-12-06 HIGH 7.8 CVE-2021-43037 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary pl… Unitrends Backup 10.5.5+ Fix from $1,9502021-12-06 MEDIUM 6.5 CVE-2021-43039 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access. Unitrends Backup 10.5.5+ Fix from $1,6002021-12-06 MEDIUM 6.5 CVE-2021-43043 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing… Unitrends Backup 10.5.5+ Fix from $1,6002021-12-06 HIGH 8.8 CVE-2021-40385 An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is a privilege escalation from read-only us… Unitrends Backup Software 10.5.5-2+ Fix from $1,9502021-09-01 HIGH 8.8 CVE-2021-40387 An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is authenticated remote code execution. Unitrends Backup Software 10.5.5-2+ Fix from $1,9502021-09-01 CRITICAL 9.8 CVE-2021-30116 KEVEPSS 86% Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page … Vsa Agent 9.5.0.24 / 9.5.7a+ Fix from $2,3002021-07-09 CRITICAL 9.8 CVE-2021-30118EPSS 60% An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and … Vsa 9.5.5+ Fix from $2,3002021-07-09 HIGH 8.8 CVE-2021-30117EPSS 72% The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. Detailed des… Vsa 9.5.6+ Fix from $1,9502021-07-09 HIGH 7.5 CVE-2021-30120EPSS 6% Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of serv… Vsa after 9.5.6 Fix from $1,9502021-07-09 HIGH 7.5 CVE-2021-30201EPSS 25% The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fet… Vsa 9.5.6+ Fix from $1,9502021-07-09 MEDIUM 6.5 CVE-2021-30121 Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: `https://x.x.x.x/KLC/js/Kas… Vsa 9.5.6+ Fix from $1,6002021-07-09 MEDIUM 5.4 CVE-2021-30119EPSS 53% Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested … Vsa 9.5.7+ Fix from $1,6002021-07-09 CRITICAL 9.8 CVE-2015-6922EPSS 82% Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly req… Virtual System Administrator 7.0.0.33 / 8.0.0.23+ Fix from $2,3002020-02-17 HIGH 8.8 CVE-2015-6589EPSS 14% Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.… Virtual System Administrator 7.0.0.33 / 8.0.0.23+ Fix from $1,9502020-02-13 MEDIUM 6.7 CVE-2019-14510 An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creates a local account FSAdm… Vsa after 9.5.0.22 Fix from $1,6002019-10-11 HIGH 7.5 CVE-2019-15506 An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An una… Virtual System Administrator after 9.4.0.37 Fix from $1,9502019-08-26 CRITICAL 9.8 CVE-2018-20753 KEVEPSS 29% Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payload… Virtual System Administrator 9.3.0.35 / 9.4.0.36+ Fix from $2,3002019-02-05 HIGH 7.4 CVE-2017-12410 It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator a… Virtual System Administrator after 9.3.0.11 Fix from $1,9502018-03-26 CRITICAL 9.8 CVE-2018-6328EPSS 65% It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unau… Unitrends Backup 10.1+ Fix from $2,3002018-03-14 CRITICAL 9.8 CVE-2017-12477EPSS 68% It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which it… Unitrends Backup 10.0+ Fix from $2,3002017-08-07