Vulnerability index

Browse CVEs

64 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2024-42020 A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection. One after 12.1.0.3208 Fix from $1,6002024-09-07 MEDIUM 5.3 CVE-2024-42022 An incorrect permission assignment vulnerability allows an attacker to modify product configuration files. One 12.2.0.4093+ Fix from $1,6002024-09-07 CRITICAL 9.8 CVE-2024-40711 KEVEPSS 90% A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). Veeam Backup \& Replication 12.2.0.334+ Fix from $2,3002024-09-07 HIGH 8.8 CVE-2024-40710 A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sen… Veeam Backup \& Replication 12.2.0.334+ Fix from $1,9502024-09-07 HIGH 8.3 CVE-2024-40714 An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credenti… Veeam Backup \& Replication 12.2.0.334+ Fix from $1,9502024-09-07 HIGH 8.0 CVE-2024-42019 A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction … One 12.2.0.4093+ Fix from $1,9502024-09-07 HIGH 7.8 CVE-2024-40712 A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation … Veeam Backup \& Replication 12.2.0.334+ Fix from $1,9502024-09-07 HIGH 7.8 CVE-2024-40713 A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication… Veeam Backup \& Replication 12.2.0.334+ Fix from $1,9502024-09-07 HIGH 8.1 CVE-2024-39718 An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to th… Veeam Backup \& Replication 12.2.0.334+ Fix from $1,9502024-09-07 CRITICAL 9.0 CVE-2024-29855EPSS 22% Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator Recovery Orchestrator 7.0.0.379 / 7.1.0.230+ Fix from $2,3002024-06-11 HIGH 7.8 CVE-2024-29853 An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation. Veeam Agent For Windows 6.1.2.134+ Fix from $1,9502024-05-22 HIGH 7.2 CVE-2024-29851 Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account. Veeam Backup \& Replication 12.1.2.172+ Fix from $1,9502024-05-22 CRITICAL 9.8 CVE-2024-29849EPSS 17% Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. Veeam Backup \& Replication 12.1.2.172+ Fix from $2,3002024-05-22 HIGH 8.8 CVE-2024-29850 Veeam Backup Enterprise Manager allows account takeover via NTLM relay. Veeam Backup \& Replication 12.1.2.172+ Fix from $1,9502024-05-22 CRITICAL 9.9 CVE-2024-29212 Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and i… Veeam Service Provider Console 7.0.0.19551 / 8.0.0.19552+ Fix from $2,3002024-05-14 HIGH 8.8 CVE-2024-22022 Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the se… Recovery Orchestrator 7.0+ Fix from $1,9502024-02-07 MEDIUM 5.4 CVE-2023-38549EPSS 19% A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the accou… One Patch available Fix from $1,6002023-11-07 CRITICAL 9.8 CVE-2023-38547EPSS 19% A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configur… One Patch available Fix from $2,3002023-11-07 HIGH 7.5 CVE-2023-27532 KEVEPSS 78% Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead… Veeam Backup \& Replication 11.0.1.1261+ Fix from $1,9502023-03-10 CRITICAL 9.8 CVE-2022-43549 Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms. Veeam Backup For Google Cloud Mitigation only Fix from $2,3002022-12-05 MEDIUM 6.1 CVE-2022-32225 A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. This vuln… Management Pack Patch available Fix from $1,6002022-07-14 CRITICAL 9.8 CVE-2022-26501 KEV Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). Veeam Backup \& Replication 10.0.1.4854 / 11.0.1.1261+ Fix from $2,3002022-03-17 HIGH 8.8 CVE-2022-26500 KEVEPSS 6% Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API … Veeam Backup \& Replication 10.0.1.4854 / 11.0.1.1261+ Fix from $1,9502022-03-17 HIGH 8.8 CVE-2022-26504 Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (… Veeam Backup \& Replication 10.0.1.4854 / 11.0.1.1261+ Fix from $1,9502022-03-17 HIGH 7.8 CVE-2022-26503 Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local s… Veeam 4.0.2.2208 / 5.0.3.4708+ Fix from $1,9502022-03-17 CRITICAL 9.8 CVE-2021-35971 Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remo… Veeam Backup \& Replication 10.0.1.4854 / 11.0.0.837+ Fix from $2,3002021-06-30 HIGH 7.5 CVE-2020-15419EPSS 60% This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati… One Firmware 9.5.4.4587 / 10.0.0.750+ Fix from $1,9502020-07-28 HIGH 7.5 CVE-2020-15418EPSS 9% This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati… One Firmware 9.5.4.4587 / 10.0.0.750+ Fix from $1,9502020-07-28 HIGH 8.8 CVE-2020-15518 VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged user… Veeam Availability Suite 10.0+ Fix from $1,9502020-07-03 CRITICAL 9.8 CVE-2020-10915EPSS 87% This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not r… One No fix yet Fix from $2,3002020-04-22