Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2024-42020
A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.
One
after 12.1.0.3208
MEDIUM 5.3
CVE-2024-42022
An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
One
12.2.0.4093+
CRITICAL 9.8
CVE-2024-40711 KEVEPSS 90%
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
Veeam Backup \& Replication
12.2.0.334+
HIGH 8.8
CVE-2024-40710
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sen…
Veeam Backup \& Replication
12.2.0.334+
HIGH 8.3
CVE-2024-40714
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credenti…
Veeam Backup \& Replication
12.2.0.334+
HIGH 8.0
CVE-2024-42019
A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction …
One
12.2.0.4093+
HIGH 7.8
CVE-2024-40712
A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation …
Veeam Backup \& Replication
12.2.0.334+
HIGH 7.8
CVE-2024-40713
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication…
Veeam Backup \& Replication
12.2.0.334+
HIGH 8.1
CVE-2024-39718
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to th…
Veeam Backup \& Replication
12.2.0.334+
CRITICAL 9.0
CVE-2024-29855EPSS 22%
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
Recovery Orchestrator
7.0.0.379 / 7.1.0.230+
HIGH 7.8
CVE-2024-29853
An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.
Veeam Agent For Windows
6.1.2.134+
HIGH 7.2
CVE-2024-29851
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.
Veeam Backup \& Replication
12.1.2.172+
CRITICAL 9.8
CVE-2024-29849EPSS 17%
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
Veeam Backup \& Replication
12.1.2.172+
HIGH 8.8
CVE-2024-29850
Veeam Backup Enterprise Manager allows account takeover via NTLM relay.
Veeam Backup \& Replication
12.1.2.172+
CRITICAL 9.9
CVE-2024-29212
Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and i…
Veeam Service Provider Console
7.0.0.19551 / 8.0.0.19552+
HIGH 8.8
CVE-2024-22022
Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the se…
Recovery Orchestrator
7.0+
MEDIUM 5.4
CVE-2023-38549EPSS 19%
A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the accou…
One
Patch available
CRITICAL 9.8
CVE-2023-38547EPSS 19%
A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configur…
One
Patch available
HIGH 7.5
CVE-2023-27532 KEVEPSS 78%
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead…
Veeam Backup \& Replication
11.0.1.1261+
CRITICAL 9.8
CVE-2022-43549
Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.
Veeam Backup For Google Cloud
Mitigation only
MEDIUM 6.1
CVE-2022-32225
A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. This vuln…
Management Pack
Patch available
CRITICAL 9.8
CVE-2022-26501 KEV
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
Veeam Backup \& Replication
10.0.1.4854 / 11.0.1.1261+
HIGH 8.8
CVE-2022-26500 KEVEPSS 6%
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API …
Veeam Backup \& Replication
10.0.1.4854 / 11.0.1.1261+
HIGH 8.8
CVE-2022-26504
Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (…
Veeam Backup \& Replication
10.0.1.4854 / 11.0.1.1261+
HIGH 7.8
CVE-2022-26503
Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local s…
Veeam
4.0.2.2208 / 5.0.3.4708+
CRITICAL 9.8
CVE-2021-35971
Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remo…
Veeam Backup \& Replication
10.0.1.4854 / 11.0.0.837+
HIGH 7.5
CVE-2020-15419EPSS 60%
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati…
One Firmware
9.5.4.4587 / 10.0.0.750+
HIGH 7.5
CVE-2020-15418EPSS 9%
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati…
One Firmware
9.5.4.4587 / 10.0.0.750+
HIGH 8.8
CVE-2020-15518
VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged user…
Veeam Availability Suite
10.0+
CRITICAL 9.8
CVE-2020-10915EPSS 87%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not r…
One
No fix yet