Barracuda records
18 published records for vendor barracuda.
Researcher profile
- Entered KEV
- 1 · 5.6%
- Weaponized
- 2 · 11.1%
- Pre-auth RCE
- 6
- With a fix record
- 11.1%
- Median publish → KEV
- 2 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-276 Incorrect Default Permissions1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2023-2868Weaponized | Remote Code injection in Barracuda Email Security Gatewaybarracuda · email security gateway 300 firmware · CWE-20 | Critical9.8 | KEV | 87.7% | May 24, 2023 |
52Plan | CVE-2023-7102Weaponized | Remote Code Execution (RCE) Vulnerabilitybarracuda · email security gateway 300 firmware · CWE-1104 | Critical9.8 | — | 44.6% | Dec 24, 2023 |
47Plan | CVE-2025-34392No exploit | Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCEbarracuda · rmm · CWE-36 | Critical10.0 | — | 24.7% | Dec 10, 2025 |
44Plan | CVE-2014-2595Proof of concept | Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authenticationbarracuda · web application firewall · CWE-613 | Critical9.8 | — | 16.9% | Feb 11, 2020 |
40Plan | CVE-2014-8428No exploit | Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.barracuda · load balancer · CWE-264 | Critical9.8 | — | 2.4% | Aug 28, 2017 |
40Plan | CVE-2014-8426No exploit | Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.barracuda · load balancer · CWE-798 | Critical9.8 | — | 2.2% | Aug 28, 2017 |
40Plan | CVE-2025-34393No exploit | Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCEbarracuda · rmm · CWE-470 | Critical10.0 | — | 0.7% | Dec 10, 2025 |
40Plan | CVE-2025-34394No exploit | Barracuda RMM < 2025.1.1 Service Center .NET Remoting Deserialization RCEbarracuda · rmm · CWE-502 | Critical10.0 | — | 0.7% | Dec 10, 2025 |
38Monitor | CVE-2017-6320Proof of concept | A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1barracuda · load balancer adc · CWE-78 | High8.8 | — | 11.1% | Jul 18, 2017 |
34Monitor | CVE-2025-34395No exploit | Barracuda RMM < 2025.1.1 Service Center .NET Remoting Path Traversal RCEbarracuda · rmm · CWE-22 | High8.7 | — | 0.8% | Dec 10, 2025 |
31Monitor | CVE-2019-6724No exploit | The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process abarracuda · vpn client · CWE-426 | High7.8 | — | 0.5% | Mar 21, 2019 |
31Monitor | CVE-2021-42711No exploit | Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions.barracuda · network access client · CWE-276 | High7.8 | — | 0.3% | Dec 1, 2021 |
30Monitor | CVE-2023-26213No exploit | On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exisbarracuda · t100b firmware · CWE-78 | High7.2 | — | 7.9% | Mar 3, 2023 |
26Monitor | CVE-2019-5648No exploit | LDAP Credential Exposure in Barracuda Load Balancer ADCbarracuda · load balancer adc firmware · CWE-522 | Medium6.5 | — | 1.1% | Mar 12, 2020 |
24Monitor | CVE-2018-20369No exploit | Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entrybarracuda · message archiver · CWE-79 | Medium6.1 | — | 0.7% | Dec 22, 2018 |
24Monitor | CVE-2025-8319No exploit | the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL barracuda · message archiver firmware · CWE-79 | Medium6.1 | — | 0.2% | Jul 29, 2025 |
17Monitor | CVE-2015-0962No exploit | Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate acbarracuda · web filter · CWE-18 | Medium4.3 | — | 1.4% | May 25, 2015 |
17Monitor | CVE-2015-0961No exploit | Barracuda Web Filter before 8.1.0.005, when SSL Inspection is enabled, does not verify X.509 certificates from upstream SSL servers, which abarracuda · web filter | Medium4.3 | — | 0.8% | May 25, 2015 |
- CVE-2023-286895Now
Remote Code injection in Barracuda Email Security Gateway
CriticalCVSS 9.8KEVWeaponizedEPSS 88%barracuda · email security gateway 300 firmwareMay 24, 2023
- CVE-2023-710252Plan
Remote Code Execution (RCE) Vulnerability
CriticalCVSS 9.8WeaponizedEPSS 45%barracuda · email security gateway 300 firmwareDec 24, 2023
- CVE-2025-3439247Plan
Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCE
CriticalCVSS 10.0No exploitEPSS 25%barracuda · rmmDec 10, 2025
- CVE-2014-259544Plan
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication
CriticalCVSS 9.8Proof of conceptEPSS 17%barracuda · web application firewallFeb 11, 2020
- CVE-2014-842840Plan
Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.
CriticalCVSS 9.8No exploitEPSS 2%barracuda · load balancerAug 28, 2017
- CVE-2014-842640Plan
Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.
CriticalCVSS 9.8No exploitEPSS 2%barracuda · load balancerAug 28, 2017
- CVE-2025-3439340Plan
Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE
CriticalCVSS 10.0No exploitEPSS 1%barracuda · rmmDec 10, 2025
- CVE-2025-3439440Plan
Barracuda RMM < 2025.1.1 Service Center .NET Remoting Deserialization RCE
CriticalCVSS 10.0No exploitEPSS 1%barracuda · rmmDec 10, 2025
- CVE-2017-632038Monitor
A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1
HighCVSS 8.8Proof of conceptEPSS 11%barracuda · load balancer adcJul 18, 2017
- CVE-2025-3439534Monitor
Barracuda RMM < 2025.1.1 Service Center .NET Remoting Path Traversal RCE
HighCVSS 8.7No exploitEPSS 1%barracuda · rmmDec 10, 2025
- CVE-2019-672431Monitor
The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process a
HighCVSS 7.8No exploitEPSS 1%barracuda · vpn clientMar 21, 2019
- CVE-2021-4271131Monitor
Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions.
HighCVSS 7.8No exploitEPSS 0%barracuda · network access clientDec 1, 2021
- CVE-2023-2621330Monitor
On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exis
HighCVSS 7.2No exploitEPSS 8%barracuda · t100b firmwareMar 3, 2023
- CVE-2019-564826Monitor
LDAP Credential Exposure in Barracuda Load Balancer ADC
MediumCVSS 6.5No exploitEPSS 1%barracuda · load balancer adc firmwareMar 12, 2020
- CVE-2018-2036924Monitor
Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry
MediumCVSS 6.1No exploitEPSS 1%barracuda · message archiverDec 22, 2018
- CVE-2025-831924Monitor
the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL
MediumCVSS 6.1No exploitEPSS 0%barracuda · message archiver firmwareJul 29, 2025
- CVE-2015-096217Monitor
Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate ac
MediumCVSS 4.3No exploitEPSS 1%barracuda · web filterMay 25, 2015
- CVE-2015-096117Monitor
Barracuda Web Filter before 8.1.0.005, when SSL Inspection is enabled, does not verify X.509 certificates from upstream SSL servers, which a
MediumCVSS 4.3No exploitEPSS 1%barracuda · web filterMay 25, 2015