İçeriğe atla
Noroxi

Veeam kayıtları

veeam üreticisine ait 78 yayımlanmış kayıt.

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

78 kayıt
  • A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90

    veeam · veeam backup \& replication7 Eyl 2024

  • Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained.

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %81

    veeam · veeam backup \& replication10 Mar 2023

  • CVE-2022-26501
    70Bu hafta

    Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %4

    veeam · veeam backup \& replication17 Mar 2022

  • CVE-2022-26500
    67Bu hafta

    Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to inte

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %6

    veeam · veeam backup \& replication17 Mar 2022

  • CVE-2020-10915
    65Bu hafta

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587.

    KritikCVSS 9,8SilahlaştırılmışEPSS %87

    veeam · one22 Nis 2020

  • CVE-2020-10914
    53Planlayın

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587.

    KritikCVSS 9,8SilahlaştırılmışEPSS %48

    veeam · one22 Nis 2020

  • CVE-2024-29849
    51Planlayın

    Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

    KritikCVSS 9,8Kavram kanıtıEPSS %38

    veeam · veeam backup \& replication22 May 2024

  • CVE-2020-15419
    48Planlayın

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415.

    YüksekCVSS 7,5İstismar yokEPSS %60

    veeam · one firmware28 Tem 2020

  • CVE-2023-38547
    45Planlayın

    A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its

    KritikCVSS 9,8İstismar yokEPSS %19

    veeam · one7 Kas 2023

  • CVE-2025-23121
    42Planlayın

    A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

    YüksekCVSS 8,8İstismar yokEPSS %24

    veeam · veeam backup \& replication18 Haz 2025

  • CVE-2025-23120
    42Planlayın

    A vulnerability allowing remote code execution (RCE) for domain users.

    YüksekCVSS 8,8İstismar yokEPSS %24

    veeam · veeam backup \& replication20 Mar 2025

  • CVE-2024-29855
    42Planlayın

    Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator

    KritikCVSS 9,0Kavram kanıtıEPSS %22

    veeam · recovery orchestrator11 Haz 2024

  • CVE-2024-29212
    39İzleyin

    Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management ag

    KritikCVSS 9,9İstismar yokEPSS %2

    veeam · veeam service provider console14 May 2024

  • CVE-2021-35971
    39İzleyin

    Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft

    KritikCVSS 9,8İstismar yokEPSS %1

    veeam · veeam backup \& replication30 Haz 2021

  • CVE-2024-39714
    39İzleyin

    A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution

    KritikCVSS 9,9İstismar yokEPSS %1

    veeam · veeam service provider console7 Eyl 2024

  • CVE-2026-21669
    39İzleyin

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

    KritikCVSS 9,9İstismar yokEPSS %1

    veeam · veeam backup \& replication12 Mar 2026

  • CVE-2026-21708
    39İzleyin

    A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.

    KritikCVSS 9,9İstismar yokEPSS %1

    veeam · veeam backup \& replication12 Mar 2026

  • CVE-2025-55125
    39İzleyin

    This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configura

    KritikCVSS 9,8İstismar yokEPSS %1

    veeam · veeam backup \& replication8 Oca 2026

  • CVE-2024-38650
    39İzleyin

    An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.

    KritikCVSS 9,9İstismar yokEPSS %1

    veeam · veeam service provider console7 Eyl 2024

  • CVE-2025-48983
    39İzleyin

    A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructur

    KritikCVSS 9,9İstismar yokEPSS %1

    veeam · veeam backup \& replication30 Eki 2025

  • CVE-2022-43549
    39İzleyin

    Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.

    KritikCVSS 9,8İstismar yokEPSS %1

    veeam · veeam backup for google cloud5 Ara 2022

  • CVE-2024-42455
    37İzleyin

    A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserializat

    YüksekCVSS 8,1İstismar yokEPSS %15

    veeam · veeam backup \& replication3 Ara 2024

  • CVE-2022-26504
    36İzleyin

    Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine

    YüksekCVSS 8,8İstismar yokEPSS %2

    veeam · veeam backup \& replication17 Mar 2022

  • CVE-2019-11569
    36İzleyin

    Veeam ONE Reporter 9.5.0.3201 allows CSRF.

    YüksekCVSS 8,8Kavram kanıtıEPSS %2

    veeam · one reporter6 May 2019

  • CVE-2025-59470
    36İzleyin

    This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or o

    KritikCVSS 9,0Kavram kanıtıEPSS %2

    veeam · veeam backup \& replication8 Oca 2026