Acronis kayıtları
acronis üreticisine ait 181 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %1,1
- Silahlaştırılmış
- 5 · %2,8
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %71,3
- Yayından KEV’e ortanca
- 2 gün
Tekrar eden sınıflar
- CWE-427 Uncontrolled Search Path Element27
- CWE-862 Missing Authorization18
- CWE-276 Incorrect Default Permissions13
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-610 Externally Controlled Reference to a Resource in Another Sphere8
- CWE-863 Incorrect Authorization8
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
181 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
85Hemen | CVE-2023-45249Silahlaştırılmış | Remote command execution due to use of default passwords.acronis · cyber infrastructure · CWE-1393 | Kritik9,8 | KEV | %53,3 | 24 Tem 2024 |
61Bu hafta | CVE-2026-87886Silahlaştırılmış | Local privilege escalation due to insecure file permissions.acronis · acronis backup · CWE-276 | Yüksek7,8 | KEV | %0,2 | 17 Eyl 2026 |
40Planlayın | CVE-2025-30411İstismar yok | Sensitive data disclosure and manipulation due to improper authentication.acronis · cyber protect · CWE-1390 | Kritik10,0 | — | %0,8 | 19 Şub 2026 |
40Planlayın | CVE-2025-30412İstismar yok | Sensitive data disclosure and manipulation due to improper authentication.acronis · cyber protect · CWE-1390 | Kritik10,0 | — | %0,7 | 19 Şub 2026 |
40Planlayın | CVE-2025-30416İstismar yok | Sensitive data disclosure and manipulation due to missing authorization.acronis · cyber protect · CWE-862 | Kritik10,0 | — | %0,5 | 19 Şub 2026 |
39İzleyin | CVE-2023-41748İstismar yok | Remote command execution due to improper input validation.acronis · cloud manager · CWE-20 | Kritik9,8 | — | %1,3 | 31 Ağu 2023 |
39İzleyin | CVE-2023-41746İstismar yok | Remote command execution due to improper input validation.acronis · cloud manager · CWE-20 | Kritik9,8 | — | %1,3 | 31 Ağu 2023 |
39İzleyin | CVE-2026-28710İstismar yok | Sensitive information disclosure and manipulation due to improper authentication.acronis · cyber protect · CWE-1390 | Kritik9,8 | — | %0,6 | 5 Mar 2026 |
39İzleyin | CVE-2024-8767İstismar yok | Sensitive data disclosure and manipulation due to unnecessary privileges assignment.acronis · acronis backup plugin for cpanel & whm · CWE-250 | Kritik9,9 | — | %0,5 | 17 Eyl 2024 |
37İzleyin | CVE-2022-3405Silahlaştırılmış | Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent.acronis · cyber backup · CWE-269 | Yüksek8,8 | — | %5,3 | 3 May 2023 |
36İzleyin | CVE-2023-44206İstismar yok | Sensitive information disclosure and manipulation due to improper authorization.acronis · cyber protect · CWE-639 | Kritik9,1 | — | %1,0 | 27 Eyl 2023 |
36İzleyin | CVE-2023-44152İstismar yok | Sensitive information disclosure and manipulation due to improper authentication.acronis · cyber protect · CWE-306 | Kritik9,1 | — | %0,9 | 27 Eyl 2023 |
36İzleyin | CVE-2023-44208İstismar yok | Sensitive information disclosure and manipulation due to missing authorization.acronis · cyber protect home office · CWE-862 | Kritik9,1 | — | %0,3 | 4 Eki 2023 |
36İzleyin | CVE-2024-49388İstismar yok | Sensitive information manipulation due to improper authorization.acronis · cyber protect · CWE-639 | Kritik9,1 | — | %0,3 | 15 Eki 2024 |
35İzleyin | CVE-2017-3219İstismar yok | Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP.acronis · true image · CWE-311 | Yüksek8,8 | — | %0,5 | 21 Haz 2017 |
32İzleyin | CVE-2020-25736Silahlaştırılmış | Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuratiacronis · true image | Yüksek7,8 | — | %2,2 | 15 Tem 2021 |
32İzleyin | CVE-2023-44154İstismar yok | Sensitive information disclosure and manipulation due to improper authorization.acronis · cyber protect · CWE-639 | Yüksek8,1 | — | %0,8 | 27 Eyl 2023 |
32İzleyin | CVE-2021-32581İstismar yok | Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653acronis · cyber protect cloud · CWE-295 | Yüksek8,1 | — | %0,7 | 5 Ağu 2021 |
32İzleyin | CVE-2024-34010İstismar yok | Local privilege escalation due to unquoted search path vulnerability.acronis · acronis cyber protect cloud agent · CWE-428 | Yüksek8,2 | — | %0,2 | 29 Nis 2024 |
31İzleyin | CVE-2022-30995Silahlaştırılmış | Sensitive information disclosure due to improper authentication.acronis · cyber backup · CWE-287 | Yüksek7,5 | — | %3,3 | 3 May 2023 |
31İzleyin | CVE-2024-34013İstismar yok | Local privilege escalation due to OS command injection vulnerability.acronis · acronis true image · CWE-78 | Yüksek7,8 | — | %0,6 | 18 Tem 2024 |
31İzleyin | CVE-2020-35145İstismar yok | Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple coacronis · true image · CWE-427 | Yüksek7,8 | — | %0,6 | 29 Oca 2021 |
31İzleyin | CVE-2020-10138İstismar yok | Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within Cacronis · cyber backup · CWE-284 | Yüksek7,8 | — | %0,5 | 21 Eki 2020 |
31İzleyin | CVE-2022-45451Kavram kanıtı | Local privilege escalation due to insecure driver communication port permissions.acronis · agent · CWE-269 | Yüksek7,8 | — | %0,5 | 31 Ağu 2023 |
31İzleyin | CVE-2020-9452İstismar yok | An issue was discovered in Acronis True Image 2020 24.5.22510.acronis · true image 2020 · CWE-59 | Yüksek7,8 | — | %0,5 | 25 May 2021 |
- CVE-2023-4524985Hemen
Remote command execution due to use of default passwords.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %53acronis · cyber infrastructure24 Tem 2024
- CVE-2026-8788661Bu hafta
Local privilege escalation due to insecure file permissions.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %0acronis · acronis backup17 Eyl 2026
- CVE-2025-3041140Planlayın
Sensitive data disclosure and manipulation due to improper authentication.
KritikCVSS 10,0İstismar yokEPSS %1acronis · cyber protect19 Şub 2026
- CVE-2025-3041240Planlayın
Sensitive data disclosure and manipulation due to improper authentication.
KritikCVSS 10,0İstismar yokEPSS %1acronis · cyber protect19 Şub 2026
- CVE-2025-3041640Planlayın
Sensitive data disclosure and manipulation due to missing authorization.
KritikCVSS 10,0İstismar yokEPSS %0acronis · cyber protect19 Şub 2026
- CVE-2023-4174839İzleyin
Remote command execution due to improper input validation.
KritikCVSS 9,8İstismar yokEPSS %1acronis · cloud manager31 Ağu 2023
- CVE-2023-4174639İzleyin
Remote command execution due to improper input validation.
KritikCVSS 9,8İstismar yokEPSS %1acronis · cloud manager31 Ağu 2023
- CVE-2026-2871039İzleyin
Sensitive information disclosure and manipulation due to improper authentication.
KritikCVSS 9,8İstismar yokEPSS %1acronis · cyber protect5 Mar 2026
- CVE-2024-876739İzleyin
Sensitive data disclosure and manipulation due to unnecessary privileges assignment.
KritikCVSS 9,9İstismar yokEPSS %0acronis · acronis backup plugin for cpanel & whm17 Eyl 2024
- CVE-2022-340537İzleyin
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent.
YüksekCVSS 8,8SilahlaştırılmışEPSS %5acronis · cyber backup3 May 2023
- CVE-2023-4420636İzleyin
Sensitive information disclosure and manipulation due to improper authorization.
KritikCVSS 9,1İstismar yokEPSS %1acronis · cyber protect27 Eyl 2023
- CVE-2023-4415236İzleyin
Sensitive information disclosure and manipulation due to improper authentication.
KritikCVSS 9,1İstismar yokEPSS %1acronis · cyber protect27 Eyl 2023
- CVE-2023-4420836İzleyin
Sensitive information disclosure and manipulation due to missing authorization.
KritikCVSS 9,1İstismar yokEPSS %0acronis · cyber protect home office4 Eki 2023
- CVE-2024-4938836İzleyin
Sensitive information manipulation due to improper authorization.
KritikCVSS 9,1İstismar yokEPSS %0acronis · cyber protect15 Eki 2024
- CVE-2017-321935İzleyin
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP.
YüksekCVSS 8,8İstismar yokEPSS %0acronis · true image21 Haz 2017
- CVE-2020-2573632İzleyin
Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configurati
YüksekCVSS 7,8SilahlaştırılmışEPSS %2acronis · true image15 Tem 2021
- CVE-2023-4415432İzleyin
Sensitive information disclosure and manipulation due to improper authorization.
YüksekCVSS 8,1İstismar yokEPSS %1acronis · cyber protect27 Eyl 2023
- CVE-2021-3258132İzleyin
Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653
YüksekCVSS 8,1İstismar yokEPSS %1acronis · cyber protect cloud5 Ağu 2021
- CVE-2024-3401032İzleyin
Local privilege escalation due to unquoted search path vulnerability.
YüksekCVSS 8,2İstismar yokEPSS %0acronis · acronis cyber protect cloud agent29 Nis 2024
- CVE-2022-3099531İzleyin
Sensitive information disclosure due to improper authentication.
YüksekCVSS 7,5SilahlaştırılmışEPSS %3acronis · cyber backup3 May 2023
- CVE-2024-3401331İzleyin
Local privilege escalation due to OS command injection vulnerability.
YüksekCVSS 7,8İstismar yokEPSS %1acronis · acronis true image18 Tem 2024
- CVE-2020-3514531İzleyin
Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple co
YüksekCVSS 7,8İstismar yokEPSS %1acronis · true image29 Oca 2021
- CVE-2020-1013831İzleyin
Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C
YüksekCVSS 7,8İstismar yokEPSS %1acronis · cyber backup21 Eki 2020
- CVE-2022-4545131İzleyin
Local privilege escalation due to insecure driver communication port permissions.
YüksekCVSS 7,8Kavram kanıtıEPSS %1acronis · agent31 Ağu 2023
- CVE-2020-945231İzleyin
An issue was discovered in Acronis True Image 2020 24.5.22510.
YüksekCVSS 7,8İstismar yokEPSS %0acronis · true image 202025 May 2021